Compliance

What OCR Enforcement Actions Teach About Risk Analysis

Anthem ($16M), Premera ($6.85M) and the pattern behind them: the same risk-analysis failures, cited over and over. What to fix before OCR notices.

The pattern

Read OCR's enforcement highlights and a pattern jumps out: the biggest settlements don't start with exotic attacks. They start with no risk analysis, or a bad one — then a breach exposes the gap, and the investigation finds the program was hollow. The breach gets the headlines; the missing risk analysis gets the penalty.

The big settlements

Turn reading into quotes. Get scoped, comparable quotes from experienced HIPAA assessors — free, 2 minutes, no obligation.

Request quotes

The five recurring failures

  1. No enterprise-wide risk analysis. Partial analyses that miss systems, or analyses never performed at all.
  2. Stale analysis. A risk analysis from years ago, never refreshed as systems and threats changed.
  3. No remediation. Risks identified but never addressed — documented negligence, which is worse than ignorance.
  4. Missing encryption. Unencrypted laptops, portable media, and backups containing ePHI, year after year.
  5. No audit controls. No mechanism to record and examine access to ePHI — so breaches go undetected.

What "OCR-quality" actually means

OCR's risk-analysis guidance specifies nine elements: scope, data collection, threat and vulnerability identification, current security measures, likelihood and impact, risk levels, and documentation. An "OCR-quality" analysis covers all of them at the information-system level — granular enough that an investigator can follow your reasoning. Anything less is a checklist with aspirations.

The pre-audit play

Twelve weeks before any assessment or audit: refresh the risk analysis, verify encryption across ePHI stores, confirm BAAs are current, and close the remediation items the analysis flagged. Walk in with the program already trending up. Score yourself first with our readiness quiz.

Keep reading

There's No Such Thing as HIPAA Certification

HHS OCR does not certify anyone. What 'HIPAA certified' vendors are actually selling — and what real compliance looks like instead.

How to Choose a HIPAA Assessment Firm: 9 Questions to Ask

No government body accredits HIPAA assessors — so vetting is on you. The nine questions that separate real healthcare assessors from generalists.

HIPAA Risk Assessment Cost in 2026: What Organizations Actually Pay

The assessment fee is the smallest line item. A full first-year cost breakdown: analysis, readiness, program build, and staff time — with planning ranges.

Questions

What's the single highest-ROI compliance activity?

A current, thorough risk analysis. It's the required foundation, the most cited enforcement failure, and the document every other control decision references.

Can OCR audit us without a complaint?

Yes — OCR runs a proactive audit program covering covered entities and business associates, separate from complaint investigations.

Turn reading into quotes

Get scoped, comparable quotes from experienced HIPAA assessors — free, 2 minutes.

Get a free quote