The envelope doesn’t look like anything. Standard government window envelope, Office for Civil Rights in the return address, and a letter that opens with either “we have received a complaint” or “we are requesting information regarding a reported breach.”
Somewhere in the second paragraph there is a deadline. Usually thirty days.
If that letter is sitting on your desk right now, here is what actually happens next, in what order, and where practices lose control of the situation.
What the letter actually is
These start one of three ways. A patient or a former employee filed a complaint. You filed a breach report yourself and OCR is following up. Or your incident made the news and OCR went looking.
What arrives first is a data request, not a penalty. Nobody has decided anything yet. That matters, because how you respond in the next three weeks shapes the outcome far more than the underlying incident does.
The first thing they ask for
Your risk analysis. Almost every time.
Not your firewall logs, not your training slides. The written analysis that identifies where electronic protected health information lives in your practice and what could go wrong with it. It is the load-bearing requirement in the whole Security Rule. Every other safeguard is supposed to be chosen based on what that analysis found, so if it does not exist, OCR’s position is that nothing downstream was chosen on any defensible basis.
Two recent settlements show how this plays out.
In July 2026, OSF Healthcare System paid $552,250 to resolve an OCR investigation. The trigger was a 2021 ransomware attack that exposed the records of 53,907 patients. The finding was that OSF had never completed an accurate and thorough risk analysis. They also agreed to a two year corrective action plan.
In March 2026, a dental software vendor called MMG Fusion settled after exposing the protected health information of roughly 15 million people. The penalty was $10,000, which sounds like nothing until you read the rest: OCR found MMG had failed to conduct a risk analysis and failed to notify the covered entities whose patients were affected. Those practices never got the chance to notify their own patients on time. Then the company dissolved, and the practices were left holding the obligation for a breach they did not cause.
The pattern is consistent. The breach is what draws attention. The missing risk analysis is what becomes the finding.
The mistake that makes everything worse
Do not backdate anything.
The temptation is obvious. You have thirty days, you do not have a risk analysis, and it would take a weekend to produce something that looks like one. Practices do this and it is the single fastest way to convert a compliance problem into a much more serious one. Documents have metadata. Vendors have records. People get deposed.
The honest answer holds up better than you would expect. “We do not have a completed risk analysis covering that period. Here is what we did have in place. Here is the assessment we have now started and the date we started it.” That is a practice with a gap. The alternative is a practice with a gap and a credibility problem.
What to do in the first week
- Put the deadline on a calendar and work backward from it. Assume you need the last week for review, not drafting.
- Do not respond the same day. Nothing good gets written in the first eight hours.
- Get counsel who has handled OCR matters specifically. Not your general business attorney, and not your malpractice carrier’s default panel unless they have this experience.
- Pull what genuinely exists. Business associate agreements, written policies, training records, prior assessments, your incident log, and access records for whatever system was involved.
- Preserve everything and suspend any automatic deletion. Email retention rules that quietly purge at ninety days have caused real problems here.
- Put one person in charge of the response. Multiple people answering OCR independently is how contradictions end up in the file.
The Arizona layer most practices forget
Arizona runs its own track alongside HIPAA. Under ARS 18-552, a breach of unencrypted personal information requires notification within forty five days of discovery. If more than one thousand Arizona residents are affected, you also have to notify the Attorney General, the Arizona Department of Homeland Security, and the three major credit bureaus.
That runs parallel to your HIPAA breach notification obligations, not instead of them. Practices that satisfy the federal requirement and assume they are finished are the ones that get a second letter.
If you have not gotten a letter
Then you have the one advantage the practices above did not: time.
Do the risk analysis. Scope it to every place ePHI actually lives, which is almost always more places than the initial list. Document what you found, what you decided to do about it, and why. Date it. Then redo it when something material changes, because a risk analysis from 2019 describing a network you no longer run is treated the same as not having one.
A few things that are not a risk analysis, despite being sold as one: a vulnerability scan, a checklist a vendor emailed you, a security questionnaire your insurance carrier sent, and anything that took under an hour.
What this looks like when it goes well
The practices that come through an OCR inquiry without a settlement are usually not the ones with the most technology. They are the ones who can produce a dated risk analysis, show what they changed because of it, and demonstrate that someone has been paying attention on an ongoing basis.
That is a documentation discipline more than a spending problem, which is genuinely good news if you are a six person practice in Gilbert rather than a hospital system.
If you want a second set of eyes
We work with Arizona medical practices on exactly this, both before a letter arrives and after one has. If you are holding one right now, the fifteen minutes is free and we will tell you honestly whether you need help or just need to get organized.
Talk to an engineer, or read more about how we support Arizona medical practices.
