The HIPAA Security Risk Analysis: The One Thing OCR Keeps Finding Missing

If you read enough Office for Civil Rights settlements you notice something. Different practices, different sizes, different incidents, and the same finding keeps appearing: no accurate and thorough risk analysis.

It is not the flashy part of HIPAA. It is a document. And it is the single most common thing OCR cites.

What it is. A written assessment of where electronic protected health information lives in your practice, what could compromise it, how likely that is and how bad it would be. It is required by the Security Rule, and it is the foundation the rest of your safeguards are supposed to sit on.

What it is not. It is not a vendor security scan. It is not a checklist somebody ticked. It is not something your EHR provider did for their own systems. Those things can feed into it. None of them is it.

Why OCR keeps finding it missing

Because it is easy to believe you have one. A practice buys good software, has a competent IT provider, keeps things patched, and reasonably concludes it is doing the right things. All true, and none of it produces the document.

OCR Risk Analysis Initiative has now produced fourteen enforcement actions. Separately, four ransomware settlements in April 2026 alone totalled $1,165,000. The practices involved were not negligent in an obvious way. They were doing roughly what most practices do.

What has to be in it

Every system, device and service that touches ePHI, including the ones nobody thinks of. Personal phones with email. The old workstation in the back office. The billing service. The scanner that emails PDFs.

The threats to each, realistically. Ransomware, lost devices, a staff member clicking something, a vendor breach.

Existing safeguards, and honestly whether they are adequate.

A risk rating, and what you plan to do about the ones that matter.

A date, and a schedule for redoing it.

The test

Could you produce your risk analysis today, with a date on it from within the last year, listing your actual systems? If a practice manager and an IT provider each think the other did it, nobody did it. That is the most common version of this failure.

Not sure where you stand? We will do a no charge review of your current position and tell you honestly whether what you have counts.

Scroll to Top