OCR (the Office for Civil Rights at HHS) enforces HIPAA. When it opens an inquiry, the process is document-driven: a letter arrives, a deadline attaches, and your paperwork either exists or it doesn’t. Here’s how to be in the first group.

How investigations start

Most begin with a breach report you filed yourself or a patient complaint. Some are audits. Small organizations are not too small: OCR’s Risk Analysis Initiative has settled cases with single-digit-clinician practices, and published settlements in the Initiative run from $10,000 to $500,000.

What OCR asks for first

The security risk analysis tops the document request, followed by the trail around it:

  • Your current security risk analysis, and prior versions
  • Remediation plans and evidence that findings were acted on
  • Policies and procedures, with review dates
  • Training records
  • Business associate agreements and vendor lists
  • Incident and breach documentation

Notice what that list rewards. Not perfection. A program: a current analysis, dated fixes, and paper behind both. OCR’s Initiative penalizes missing preparation, not breach size.

Before any letter: three moves

  1. Get the risk analysis current. An analysis describing systems you no longer use is worse than none in one way: it proves you knew the requirement.
  2. Date your remediation. Every finding needs an owner, a date, and evidence of the fix. This trail is what settles inquiries.
  3. Keep the annual rhythm. A yearly refresh is the difference between a program and a binder.

If the letter already arrived

Call a healthcare attorney first; the response itself is legal work. Then move fast on the security documentation with whoever performs your assessments. Two things matter: respond by the deadline, and never backdate anything. A truthful “here is what exists today and here is our dated plan” is a defensible position; a forged date is a career-ending one.

The honest summary

You cannot control whether a letter comes. You control whether the answer already exists. Organizations with a current, defensible risk analysis and a documented remediation record resolve inquiries; organizations without them fund the enforcement statistics.