Blog / US compliance
US compliance
The HIPAA Risk Analysis: What OCR Actually Fined Practices For in 2025 and 2026
A HIPAA risk analysis is the document OCR asks for first. What it is, why annual training does not count, and how a small practice writes one that holds up.
The letter asks for one document
The practice administrator of a two-location dermatology group has run HIPAA training every March for six years. She keeps the certificates in a binder, alphabetized. She has the EHR vendor's compliance attestation, a laminated notice of privacy practices at both front desks, and a business associate agreement with the billing company.
In May a laptop holding the patient photo archive goes missing from the satellite office. She reports it, as she should. In August a letter arrives from the Office for Civil Rights. The letter does not ask about training. It asks for a copy of the practice's most recent risk analysis, the risk management plan that came from it, and the dates of both.
She searches the shared drive for "risk". She finds a fire risk form from the landlord. The IT company sends over a network diagram and a scan report from 2023 and says, kindly, that they thought the practice had that covered.
There is no document. There never was. Six years of training, two locations, forty thousand patient records, and the one thing the regulator asks for first does not exist.
This administrator did nothing lazy. She did what every vendor told her HIPAA compliance was. Nobody told her what it actually is.
What a risk analysis is, in plain words
A HIPAA risk analysis is a written, honest answer to four questions. Where does electronic patient information live in this practice? What could go wrong with each of those places? How likely is that, and how bad would it be? What are we doing about it? The Security Rule calls it "accurate and thorough", and the Office for Civil Rights, the HHS office that enforces HIPAA, reads those two words literally.
ePHI is electronic protected health information: any patient detail stored or sent digitally, from the EHR to the intraoral camera laptop to the recall texting tool.
A risk management plan is the second document: the list of what you decided to fix, who owns each item, and by when.
A resolution agreement is the settlement OCR signs with a practice after an investigation, usually a payment plus a corrective action plan that runs for two or three years.
Training is not a risk analysis. A vendor's certificate is not a risk analysis. The civil penalty tiers for 2026 run from $145 to $2,190,294 per violation category, effective 28 January 2026, and the tier depends partly on what the practice could have known. A missing risk analysis is the definition of could have known.
The numbers that matter
OCR closed 21 HIPAA settlements in 2025 and collected $8.33 million, with most of those cases tied to a single provision, the risk analysis requirement, according to HIPAA Journal's 2026 enforcement review. One paragraph of the rule accounts for most of the money.
In February 2026 OCR announced its 11th and 12th enforcement actions under the Risk Analysis Initiative, per HHS OCR's 2026 announcements. The initiative exists because the same finding kept appearing in investigation after investigation.
Hacking incidents made up 87% of healthcare breaches in the first half of 2026, according to HIPAA Journal's 2026 analysis. The risk analysis is the document that would have shown where the hackers were going to get in.
What to do this week
- Make the ePHI map. One page: every system, device, app and inbox that holds patient information, including the ones outside the EHR. Walk both locations with a clipboard; do not do this from memory. (CIS 3 Data Protection)
- Run a vulnerability scan on every computer and network device on that map, and keep the report. An unpatched front-desk PC is a risk you must write down, not one you get to skip. (CIS 7 Continuous Vulnerability Management)
- Build the risk register from the map: for each place ePHI lives, the threat, how likely, how bad, and your decision. A spreadsheet with twenty rows you wrote beats a 90-page template nobody read. (CIS 3 Data Protection)
- Turn the decisions into the risk management plan with an owner and a date beside each one. "Encrypt the photo archive laptop, office manager, 30 September" is a plan. "Improve encryption" is not. (CIS 7 Continuous Vulnerability Management)
- Write the breach decision procedure now: who judges whether an incident is reportable, using which logs, within how many days. The 60-day clock will not wait while you design the process. (CIS 17 Incident Response Management)
- Sign and date both documents, then put the next review on the calendar twelve months out and after any major change, such as a new EHR or a new location. (CIS 17 Incident Response Management)
Where AccuSights fits
Our assessment is the risk analysis, written the way OCR reads it: the ePHI map, the threats, the decisions and the plan, in a practice's own language. Our team implements the controls that come out of it at a reasonable rate, from data loss prevention to scanning to protecting the devices that hold records. In major US cities one of our cybersecurity engineers comes on site, sets up the critical controls and the protection agent, and the office is protected the same week. Start with the three-minute Cyber Hygiene Test, or book 15 minutes with an engineer.
Questions people ask
How often does HIPAA require a risk analysis? The Security Rule does not give a number of months. It requires the analysis to be current, which OCR reads as reviewed regularly and updated whenever something material changes: a new EHR, a new location, a merger, a breach. Practices that hold up under investigation review it every year and after every significant change, and can show the dates.
Is a risk analysis the same as a risk assessment? In HIPAA's own language the required document is the risk analysis, and the fixes that follow are risk management. Many vendors, and the HHS tool itself, say security risk assessment for the same thing. The name on the cover matters less than the content: an inventory of where ePHI lives, the threats to each place, and a documented decision for each one.
Can I do a HIPAA risk analysis myself? Yes, and a small practice that does it thoroughly is in a better position than one that paid for a template and never opened it. The limit is technical: someone has to find the unpatched device, the open remote access and the unencrypted laptop, because a risk you cannot see never makes it into the register. Do the map and the decisions yourself, and get help with the scanning.
A risk analysis is the practice examining itself. Skip it, and someone else will do the examination for you, at a time of their choosing.
Controls this post maps to
CIS Controls v8.1. These are the same controls our assessment scores and the console watches.
Sources
Dr. Kashmala Khalid, Co-Founder, healthcare and defense programs. The clinical and regulatory authority behind the HIPAA and CMMC programs. Compliance with the precision of a surgeon and none of the fear-mongering. About the team →
Keep reading
Three more from the same shelf.
The HIPAA Security Rule Update Is Still a Proposal. The MFA Clock Is Not.
The HIPAA Security Rule update 2026 is still a proposal, with finalization projected for July 2027. Why MFA and encryption cannot wait for the final text.
US complianceThe 2027 Cybersecurity Calendar for US Small Business: The Dates That Are Real, and the One Everybody Is Guessing About
A US cybersecurity regulatory calendar for 2027: the confirmed dates from January to December, which ones apply to a 40-person company, and what to do first.
US complianceThe HIPAA Security Rule Rewrite: The Dates to Budget Around and the Controls That Stop Being Optional
HIPAA Security Rule update timeline: the proposal is not final and HHS projects July 2027, so here are the controls to budget for and the dates to plan around.
