HIPAA Series: Risk Analysis - OCR's Most-Cited Deficiency - And Most Entities Are Still Failing It

If you looked at every HIPAA Security Rule enforcement action OCR has taken over the past decade, one deficiency appears more than any other: inadequate risk analyses. Not missing MFA, not unencrypted devices, but risk analyses.

Don’t take my word for it! OCR's January 2026 Cybersecurity Newsletter stated it plainly: risk analysis is the most frequently cited deficiency in OCR investigations. The requirement has been in the Security Rule since 2003. It has appeared in major settlements for 20 years, from the $16 million Anthem settlement in October 2018 (arising from a 2015 breach of almost 79 million records and a finding of inadequate enterprise-wide risk analysis) to the April 2026 ransomware settlements totaling $1,165,000. The pattern doesn't change: a breach occurs, OCR investigates, and the investigation finds the covered entity either didn't have a risk analysis or had one that wasn't adequate.

In fall 2024, OCR formalized this enforcement focus by launching the Risk Analysis Initiative. This was a targeted campaign specifically aimed at organizations that hadn't conducted comprehensive, documented security risk assessments. By mid-2026, the initiative had produced at least 12 enforcement actions. Settlement amounts range from $10,000 for a small surgical practice to $350,000 for larger organizations, with mandatory two-to-three-year corrective action plans attached to each.

In April 2026, OCR's Senior Advisor for Cybersecurity Nick Heesters expanded the enforcement signal further: OCR is now examining not just whether organizations conduct risk analysis, but whether they act on what they find. "Failing to take action to mitigate risks or implementing security measures that do not sufficiently reduce risks to a reasonable and appropriate level is something OCR discovers frequently," Heesters said. The analysis is necessary, but OCR now treats the failure to act on findings as independently enforceable.

The 2026 Security Rule proposed update raises the standard further. If your current risk analysis didn't satisfy OCR before, it almost certainly won't satisfy the new requirement.

What the rule actually requires

The existing Security Rule requires covered entities to conduct an "accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information." That language has been in place since 2003. The enforcement problem was never the standard however. It was that the standard was vague enough that organizations could produce something that looked like a risk analysis without satisfying what OCR was actually looking for.

The 2026 proposed rule replaces that vagueness with specificity. A compliant risk analysis under the updated rule must include:

A complete ePHI inventory. Before you can assess risk to patient data, you need to know where it exists. Every system, device, application, and location where ePHI is created, received, maintained, or transmitted must be inventoried and documented. The proposed rule requires this asset inventory to be reviewed and updated annually. It's the predicate for everything else and if you don't know where your data is, your risk assessment covers an unknown fraction of your actual exposure.

Documented threat and vulnerability identification. For each asset in the inventory, the risk analysis must identify specific threats, i.e. what could cause harm to that asset, and specific vulnerabilities, i.e. what weaknesses make each threat exploitable. "We could get hacked" is not a documented threat. "Ransomware infection via phishing email compromising workstation credentials" is. The difference will matter a lot when OCR reviews your documentation.

Likelihood and impact ratings. Each identified threat-vulnerability pair must be assessed for the probability of occurrence and the potential impact if it materializes. The proposed rule requires these assessments to be documented with the methodology used, not just the result. A risk matrix showing how each threat was evaluated is the expected output.

A written risk management plan. The risk analysis is the beginning of a process, not a deliverable to file and forget. The findings must generate a documented risk management plan, specific actions to address identified risks, in priority order, with timelines and responsible parties. This is where most entities will fail the enforcement standard, and it's where OCR's April 2026 guidance makes the enforcement theory explicit: identifying a risk and failing to address it is not substantially better than never identifying it.

Version control and dating. The proposed rule requires the risk analysis to be demonstrably current. A document without a date, without revision history, without evidence of review following operational or environmental changes doesn't demonstrate compliance. It demonstrates that a document was produced.

Why I think most organizations will fail it

There are three common failure modes, and most entities have at least one.

The checkbox risk analysis. An organization engages a vendor or consultant who provides a questionnaire-based assessment and generates a report. The report gets filed, the engagement ends, and the compliance calendar moves on. Two years later, the same organization has added a telehealth platform, onboarded a new billing vendor, and started allowing remote EHR access on personal devices, but the risk analysis still reflects the environment from two years ago.

OCR's position, consistent across every enforcement action, is that a risk analysis is a process, not a document. The document is evidence of the process. When the environment changes, the process must continue. A two-year-old risk analysis for a company that has added new technology, new vendors, or new workflows is not a compliant risk analysis. It is simply an outdated document.

Scope gaps. Many entities scope their risk analysis to the EHR and stop there. The Security Rule covers all ePHI — email, practice management software, billing systems, patient portal platforms, cloud storage, backup environments, portable devices, and any other location where patient data exists. A risk analysis that covers the EHR and ignores the billing vendor's access to the same data has assessed part of the attack surface.

The average healthcare organization has dozens or hundreds of business associate relationships. Each one represents an ePHI access point. Even though it could be a huge life, each BAA belongs in the risk analysis scope.

Vague findings. A risk analysis that produces findings like "there is a risk of unauthorized access" without identifying the specific vulnerability, rating the likelihood, assessing the impact, and connecting it to a mitigation action doesn't satisfy the requirement. OCR has been explicit about this in settlement language and guidance documents for years. The analysis must be specific enough to generate an actionable risk management plan and the risk management plan must actually be executed. I’m not advocating with placing a specific dollar amount on your potential risk, that might not be the strategy you want (talk to your legal counsel about that), but I am finding that there needs to be a level of greater specificity that an organization typically thinks.

What OCR is actually looking for

The Risk Analysis Initiative has clarified what OCR expects, not through policy guidance but through enforcement action. The corrective action plans in these settlements (which are public) describe the compliance program OCR requires organizations to build or rebuild after a finding.

Common elements across corrective action plans from 2024-2026:

Annual risk analysis updates, documented and signed. A risk management plan that addresses each identified risk with specific actions and timelines. Evidence that the risk management plan was actually implemented and not just written. Audit log review procedures documented and followed. Workforce training on risk analysis and security awareness with attendance records. Annual reporting to OCR on compliance status.

In April 2026, Heesters made the enforcement standard explicit in formal guidance: "Policies and procedures alone are not sufficient evidence of security measure implementation." OCR wants to see that identified risks drove real decisions, configurations changed, controls deployed, measures documented. A written risk management plan that was filed and never implemented is evidence of the same failure the plan was supposed to address.

Willful neglect - the classification OCR applies when organizations know about risks and do nothing -carries a minimum penalty of $73,011 per violation for violations not corrected within 30 days. OCR can treat each day of continuing non-compliance as a separate violation, which is how penalties compound into the millions.

What a compliant risk analysis looks like

For a small to mid-sized medical practice, a compliant risk analysis under the proposed rule is a substantive document; typically 20 to 40 pages for a smaller practice, longer for a multi-provider group. It includes:

An asset inventory listing every system and location where ePHI exists, with system owner, ePHI type, access method, and current security controls documented for each.

A threat-vulnerability matrix covering each asset, identifying threats specific to that asset type, the vulnerabilities that make each threat exploitable, and a likelihood-impact rating with the methodology used.

A risk rating summary that aggregates findings by severity and identifies the highest-priority risks.

A risk management plan with specific actions tied to each high and medium-risk finding, assigned owners, target completion dates, and status tracking.

A review and update log showing when the analysis was last reviewed, what triggered the review, and what changes were made.

The analysis gets updated annually at minimum and whenever there's a significant operational change, i.e. a new EHR, a new vendor, a new telehealth platform, a change in how staff access systems remotely. Each update gets documented with a date and a summary of what changed.

The new scanning and testing requirements

The proposed 2026 rule adds specific vulnerability management requirements that interact with risk analysis: vulnerability scanning every six months and annual penetration testing. These aren't optional additions. They generate findings that must feed back into the risk management plan.

A company that completes an annual risk analysis and then discovers new vulnerabilities through mid-year scanning is expected to update its risk management plan to address those findings. The documentation cycle is continuous, not annual.

For entities that have never engaged a security firm for penetration testing, this is a new budget line. Basic external penetration testing for a small medical practice typically runs $3,000 to $8,000 annually depending on scope and vendor. Set against an average healthcare breach cost of $9.77 million (per IBM's 2024 Cost of a Data Breach Report, the highest of any industry) the math isn't complicated.

Where to start

If your last risk analysis is more than a year old, treat it as expired. The environment has changed, the rule has changed, and OCR is actively investigating organizations whose documentation doesn't match their current infrastructure, under the existing rule, before the proposed update even finalizes.

Start with the inventory. Before any analysis can proceed, you need to know where your ePHI lives. Period. All systems, all devices, all vendors with access, and all locations including cloud platforms, backup systems, and portable devices. This is the work that makes everything else possible.

Then engage a qualified professional to conduct the assessment. not a questionnaire vendor, but someone who will actually evaluate your specific environment. OCR can tell the difference when it reviews documentation, and the corrective action plans from recent enforcement actions make clear what a compliant assessment looks like versus a checkbox exercise.

Build the risk management plan as part of the same engagement, and then actually use it. The analysis is only valuable if it generates documented action. A a risk management program is not just a list of findings with no remediation timeline and no evidence of implementation. Don’t let your risk management documentation match the fact pattern in every recent enforcement action.

The compliance deadline runs 180 days from whenever the final rule publishes. Risk analysis is one of the longer-lead items in the compliance project because doing it correctly takes time. It's also the one OCR is actively enforcing right now, before the final rule is even published.

Next up in this series, we’ll finish with: business associate agreements. If your vendor contracts predate 2025, they almost certainly need updating.

If you need help structuring a risk analysis that holds up to OCR scrutiny, schedule a consult @ https://jharrisadvisory.com/contact.

For the full picture — proposed changes, readiness plan, and toolkit — see our HIPAA Security Rule NPRM guide

Previous
Previous

HIPAA Series: BAAs - Every Vendor Contract You Signed Before 2026 Needs a Second Look

Next
Next

The Federal AI Bill Isn't About Your Business - And That's the Problem