Compliance · 2026-07-27 · 7 min read
OCR Just Expanded HIPAA Enforcement to Risk Management — Is Your Practice Exposed?
OCR’s Security Risk Analysis Initiative just expanded from "did you do a risk analysis?" to "did you act on it?" Four new April 2026 settlements ($10K–$350K+) hit practices that identified risks and never fixed them. Here’s what OCR now looks for — and how to close the gap this week.
You did your risk analysis. You filed it. You checked the box. OCR doesn't care about the box anymore.
For years, the question in a HIPAA investigation was simple: did you do a security risk analysis? If you could produce one, you had cleared the single most-cited requirement in the Security Rule. That era is over. The Office for Civil Rights has quietly moved the goalposts — and if your compliance program still ends at "we have a risk analysis on file," you are exposed in a way you probably haven't measured.
What actually changed
In October 2024, OCR launched its Security Risk Analysis Initiative — a focused enforcement push targeting one requirement: 45 CFR 164.308(a)(1)(ii)(A), the rule that says you must actually assess the risks to your electronic protected health information. In under 18 months it produced more than a dozen settlements, most of them small-dollar, all making the same point: a lot of practices had never done a real risk analysis at all.
Then, in April 2026, OCR expanded the initiative — and this is the shift almost nobody is ready for. The scrutiny moved one clause down the page, to 45 CFR 164.308(a)(1)(ii)(B): risk management. Risk analysis asks what could go wrong. Risk management asks what you did about it. OCR is no longer satisfied that you identified your risks. They want to see that you acted on them.
That is a fundamentally harder bar to clear, because it turns your own paperwork into evidence. A risk analysis that lists ten unaddressed vulnerabilities is no longer proof of diligence — it is a documented list of problems you knew about and left alone.
It also flips the burden of proof onto you. In a HIPAA investigation, the organization has to demonstrate compliance — OCR doesn't have to prove you were careless, you have to prove you weren't. When the standard was "do you have a risk analysis," a single document met that burden. Now the burden is "prove you managed the risks you found," and that can only be met with a trail of decisions and evidence built up over time. You cannot reconstruct it the week the letter arrives.
The enforcement pattern that keeps repeating
The cases follow an almost identical script:
- A practice gets hit with ransomware — still the most common trigger — or reports a breach for some other reason.
- OCR opens an investigation and asks for the security risk analysis.
- The practice produces one — often a decent document, sometimes several years old.
- OCR reads it, finds the specific gaps it identified — no encryption on laptops, no multi-factor authentication, a flat network with no segmentation — and asks the question that ends the meeting: "You identified this in 2019. Show me what you did about it."
- There is no answer. The finding was never remediated. A settlement follows, along with a two-to-three-year corrective action plan that puts the practice under active OCR monitoring.
The April 2026 wave brought four new settlements, ranging from roughly $10,000 to over $350,000. The common thread was not that these practices skipped the risk analysis — several had done one. It was that the risks they found were never fixed.
The low end of that range matters as much as the high end. A $10,000 settlement against a small rural practice is OCR sending an unmistakable message: there is no "too small to investigate." If anything, small practices are more exposed, because they are the ones most likely to have run a single analysis years ago, filed it, and never looked at it again.
And the dollar figure is often the least painful part. The corrective action plan attached to these settlements typically runs two to three years and requires the practice to redo its risk analysis to OCR's satisfaction, build a written risk management plan, submit it for approval, implement it on a deadline, and file regular progress reports the whole time. In practice that means a small office spends the next few years doing supervised compliance work — the exact work that, done a year earlier and voluntarily, would have avoided the investigation entirely.
What OCR actually looks for now
If an investigator landed in your office next week, "acting on your risk analysis" would be measured against five things:
- A current risk analysis. Not one from three years ago. Your environment changed — new devices, new vendors, new cloud tools, new staff. A stale analysis is arguably worse than none, because it proves you knew the process and then stopped.
- A documented decision for every identified risk. For each risk, OCR expects to see one of four choices, made deliberately: mitigate it, accept it, transfer it (to insurance or a vendor), or avoid it (stop doing the risky thing). Silence is not a decision.
- Proof that mitigations were actually implemented — not planned, not scheduled, done. "We intended to roll out MFA" is not a defense. A dated record showing MFA was turned on across the practice is.
- Ongoing monitoring. Risk management is a cycle, not an event. OCR wants evidence that you re-assess periodically and after major changes — not that you did it once in 2022.
- A documentation trail. Who decided what, when, and why. If a risk was accepted rather than fixed, there should be a record of who made that call and the reasoning behind it.
Notice the through-line: every one of these is about evidence, not intentions. OCR does not grade effort. It grades what you can produce.
The "good enough" trap
Here is where a lot of well-meaning practices get caught. They believe they are covered because they have something:
- The EHR vendor's template. A generic questionnaire your EHR provider handed you is a starting point, not a risk analysis. It doesn't know your building, your network, your workflows, or the laptop a nurse takes home. OCR has been explicit for years that a risk analysis must be specific to your organization.
- The one-time consultant visit. A consultant who spent an afternoon on-site two years ago and left a PDF gave you a snapshot, not a program. If nothing has been updated since, you have a document, not a defense.
- The checklist you filled out once. Answering yes or no to a list of controls is not the same as identifying, ranking, and managing risks over time.
None of these are worthless — but none of them, on their own, answers the question OCR is now asking. They tell you what your risks were. They say nothing about what you did.
What to do this week
You don't need a consultant to start closing this gap. You need an afternoon and an honest look at your own file:
- Pull out your most recent risk analysis and check the date. If it's more than a year old, or predates a major change (new EHR, new location, a shift to remote work), it needs to be refreshed.
- Go line by line through the risks it identified. For each one, ask: is there a documented decision — mitigate, accept, transfer, or avoid?
- For every "mitigate," find the proof. Is there evidence the fix was actually implemented, with a date? If the analysis said "encrypt laptops" and you can't show that laptops are encrypted, that is your highest-priority gap — today.
- Write down the "accept" decisions. If you consciously accepted a risk, record who decided and why. An accepted risk with a rationale is defensible. An ignored risk is not.
- Put a recurring reminder on the calendar — quarterly is a reasonable cadence — to re-review your risks and log any changes.
- Document everything as you go. The single most repeated lesson in every OCR settlement is the same: if it isn't written down, it didn't happen.
If that exercise turns up risks you identified but never resolved, don't panic — but don't wait, either. A gap you are actively closing, with a dated plan, is a very different conversation with OCR than a gap that has sat untouched since 2019.
How Shieldra helps
This is exactly the problem Shieldra is built to solve. The platform runs continuous risk assessment — not a once-a-year snapshot — and pairs every identified risk with remediation tracking, so each one carries a documented decision and a status you can actually prove. Every risk gets a decision trail: what was chosen, by whom, when, and why. And an audit-readiness score tells you, in plain terms, whether your risk management would hold up under the exact scrutiny OCR is now applying — before OCR is the one asking.
We'll be honest about the division of labor: we handle the documentation and the tracking; the judgment calls are yours. Whether to mitigate a given risk or accept it is a decision only your practice can make — but we make sure that when you make it, it's captured, dated, and ready to show. That is the difference between a risk analysis that sits in a drawer and a risk-management program that survives an investigation.
Take a free risk assessment
The fastest way to find out where you stand is to look. Take a free risk assessment and see which of your risks already have a documented decision behind them — and which are still sitting exposed. It takes minutes, and it's a great deal cheaper than the version OCR runs for you. For the wider context on what these incidents cost, our healthcare data breach statistics are updated continuously.
The goalposts moved. The good news is that catching up is mostly a matter of connecting decisions to evidence — and that is a problem you can start solving this afternoon.