Blog
/
HIPAA
/
HIPAA violation autopsy: What 100 OCR settlements actually reveal

HIPAA violation autopsy: What 100 OCR settlements actually reveal

5
min read
Published on
Jul 29, 2026
Updated on
Jul 29, 2026
Authored by
Susmita Joseph
Content Writer
reviewed by
Team Scrut
Table of contents
Key Takeaways
  • Most HIPAA OCR settlements stem from four recurring failures: inadequate risk analysis, weak access controls, deficient BAAs, and missed breach notification deadlines.
  • OCR expects continuous compliance, not one-time audits. Organizations must demonstrate ongoing risk management, access reviews, vendor oversight, and documented controls.
  • Risk analysis is OCR's top enforcement priority. An outdated or missing risk analysis is one of the most common findings in HIPAA settlements.
  • Strong operational processes reduce enforcement risk. Regular reviews, complete BAA management, and tested breach response procedures help organizations stay audit-ready.

OCR has published every HIPAA settlement it has reached since enforcement began. The record now runs past 100 resolution agreements, and the pattern it reveals is specific enough to be useful. The same four or five failure categories appear in case after case, across covered entities of every size, in every care setting.

This is not a list of violations. It is an analysis of the conditions that make those violations predictable, and what the enforcement record tells compliance teams about where to focus before an investigation begins.

What the enforcement record actually shows

According to HIPAA Journal's enforcement tracking, OCR closed 22 enforcement actions in 2024 and 21 in 2025, the two busiest years on record for HIPAA enforcement. From January through August 2025 alone, OCR announced 16 resolution agreements. As of April 2026, OCR has completed 19 ransomware investigations and 13 Risk Analysis Initiative investigations, with four additional ransomware settlements announced in a single day in April 2026 covering $1.165 million and 427,000 affected individuals. The average time between OCR receiving a complaint and announcing a settlement is 57 months. The median is 62 months. The longest case in the recent enforcement period ran 88 months from complaint to resolution.

That timeline matters operationally. An investigation that opens today following a breach report will not close for years. The corrective action plan, the monitoring obligations, the reputational exposure, and the financial settlement all sit on the calendar well into the future. The compliance program in place today determines how that investigation goes.

Settlements moved 14 months faster on average than civil monetary penalties. The organizations that cooperated and demonstrated genuine remediation consistently reached resolution sooner and paid less.

Across the 2024 and 2025 enforcement cycles, one finding dominated above all others. Inadequate risk analysis appeared in 13 of 20 matters examined in one enforcement period analysis and cited across the majority of ransomware settlements since. OCR launched its Risk Analysis Initiative in October 2024, specifically because this gap had become endemic. By April 2026, the initiative had produced 13 resolution agreements, and OCR has confirmed it will expand the initiative in 2026 to also cover risk management failures. The other high-frequency findings were information system activity review failures, access control lapses, and unauthorized disclosures.

The four failure patterns that drive most settlements

HIPAA settlements rarely result from obscure or highly technical violations. They arise from operational failures that organizations knew they needed to address but never embedded into day-to-day processes. OCR investigations consistently show the same pattern: policies exist, security controls are partially implemented, but the documentation, governance, and ongoing oversight needed to demonstrate compliance are missing.

Across recent enforcement actions, four failure patterns appear repeatedly. Organizations fail to maintain an accurate risk analysis, access controls drift without oversight, Business Associate Agreements contain structural gaps, and breach notification obligations are missed because operational processes cannot keep pace with regulatory timelines. Understanding these patterns is more valuable than memorizing every HIPAA requirement because they explain where OCR spends its attention and why organizations ultimately enter corrective action plans.

1. Risk analysis that was never done, or done once and abandoned

OCR’s Risk Analysis Initiative targets entities that failed to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to electronic protected health information. The language is precise because the failure is precise. Organizations either never conducted a risk analysis at all, or conducted one years earlier and treated it as a permanent artifact, never updated as systems, vendors, and workflows changed.

Vision Upright MRI, a California imaging provider, had never conducted a risk analysis before OCR initiated a compliance review following a breach exposing 21,778 individuals. The settlement was $5,000. But the corrective action plan required a full risk analysis, a risk management plan, updated policies, and workforce training across a two-year monitoring period. The financial settlement was minor. The operational obligation was not.

OCR now expects risk analysis to be conducted at least annually and repeated whenever material changes occur in systems, workflows, or data practices. A risk analysis that predates a major system migration, a new cloud vendor, or a significant expansion in workforce access does not satisfy the requirement.

OCR can request copies of all risk analysis reports going back as far as six years during a breach investigation. A short summary report will not be sufficient to demonstrate that the analysis was accurate and thorough.

2. Access controls that exist on paper but not in practice

BayCare Health System paid $800,000 to resolve an investigation that began with a complaint about a former employee accessing patient records after termination. OCR found that BayCare had not restricted access upon the employee's termination, lacked policies to prevent improper credential use, and had not implemented sufficient controls to detect unauthorized access. The investigation also found failures in the information system activity review.

The BayCare case reflects a pattern OCR encounters consistently. Access control policies exist, but the operational process around them breaks down at the edges. Former employee credentials stay active. Shared accounts accumulate. Privileged access expands without formal review. The gap between the policy and the practice is where most access control findings live.

The access recertification gap is where organizations lose the most ground between assessments. Formal access reviews conducted quarterly and documented with completion records give compliance teams something to show when an assessor asks how privileged access is managed. Without those records, the technical controls in place carry no weight. OCR's 2024 proposed Security Rule updates would make MFA mandatory, require 24-hour notifications of access changes, and mandate regular reviews of information system activity. Those proposals remain pending, but enforcement under the existing rule already treats access control lapses as a serious finding.

3. Business Associate Agreements (BAA) with structural gaps

In 2024/25, BAA deficiencies appeared across OCR's 22 enforcement actions, with OCR collecting over $9.9 million in total settlements that year. The March 2026 settlement with MMG Fusion, a dental practice software vendor, is instructive: an unauthorized actor infiltrated the company's systems in December 2020 and posted patient names, phone numbers, addresses, dates of birth, and appointment details on the dark web. OCR found three violations, impermissible disclosure, failure to conduct a risk analysis, and failure to notify affected covered entities of the breach. The settlement amount was $10,000 with a three-year corrective action plan.

The most common BAA failures OCR encounters are structural, not incidental. A vendor handles PHI with no signed agreement in place. Subcontractor flowdown is missing, so the vendor's vendors operate without HIPAA obligations. Breach-reporting clauses contain no deadline, no designated contact, and no definition of what qualifies as a security incident. Agreements signed before the 2013 Omnibus Rule are still in use and lack the required elements.

The BAA inventory problem compounds during periods of organizational growth. A billing vendor onboarded during a system migration, a cloud storage provider added for operational convenience, a scheduling platform implemented without a compliance review, each of these creates PHI exposure without a corresponding legal obligation on the vendor. OCR does not treat a missing BAA as an administrative oversight. It treats it as a violation that existed from the moment PHI moved to an unbound vendor, regardless of whether a breach occurred. The compliance exposure is retroactive to the date the relationship began, which is why BAA inventory management is most accurately framed as a vendor onboarding discipline, not a pre-audit task.

OCR treats a missing or deficient BAA as grounds for a higher penalty calculation. And the BAA file is one of the first things OCR requests after a breach report. An organization that cannot produce executed agreements for every active vendor with PHI access has a documented compliance gap that predates the breach.

General-purpose AI tools, including public versions of widely used platforms, do not execute HIPAA BAAs. Inputting PHI into these platforms is a HIPAA violation. As AI tools enter clinical and administrative workflows, BAA inventory must expand to cover them.

4. Breach notification timelines that were missed

The Breach Notification Rule requires covered entities to notify affected individuals within 60 days of discovering a breach of unsecured ePHI. For breaches affecting 500 or more individuals, notification to OCR and relevant media outlets is also required within that window. Business associates must notify covered entities without unreasonable delay and no later than 60 days from discovery. The discovery date is the trigger, not the date the organization confirms the full scope of the breach. Organizations that wait for a forensic investigation to conclude before starting the notification clock are regularly surprised to find that the 60-day window closed before their investigation did.

Vision Upright MRI did not issue breach notifications to affected individuals, HHS, or the media within the 60-day window. Comstar, a Massachusetts billing and collections company, paid $75,000 and entered a two-year corrective action plan in part because of failures in breach notification. These cases sit alongside years of enforcement showing that the 60-day deadline is treated as absolute, not aspirational.

The operational risk in the 60-day window is compounding. A business associate that reports a breach on day 59 leaves the covered entity one day to notify affected individuals, coordinate media notification, and submit to OCR. Well-constructed BAAs shorten the internal reporting obligation to 5 to 10 business days or 72 hours for security incidents, giving covered entities time to act.

The compliance gaps OCR finds most preventable

Looking across the enforcement record, OCR's corrective action plans point to the same set of operational gaps. These are not exotic control failures. They are foundational program requirements that were skipped, deferred, or let drift.

  • No current, documented risk analysis. The risk analysis requirement is the most cited finding in recent enforcement. It must be thorough, documented, and repeated. A summary document will not survive scrutiny.
  • Workforce access not reviewed or revoked on termination. OCR finds former employee credential access in enforcement action after enforcement action. Access review and revocation processes need documented evidence of execution; a policy describing the process is a starting point, not a demonstration of compliance.
  • Incomplete BAA inventory. Every vendor that creates, receives, maintains, or transmits PHI on your behalf requires an executed BAA before PHI flows to them. Cloud storage providers, billing platforms, AI tools, scheduling software, and analytics services all fall within this definition.
  • No documented information system activity review. Audit logs without a review process do not satisfy the HIPAA Security Rule. OCR cited activity review failures in 6 of the 20 recent enforcement actions. The review must happen on a defined schedule with documented outcomes.
  • Breach notification processes that are not rehearsed. The 60-day clock starts at discovery. Organizations that have not mapped their breach response process before an incident occurs consistently miss the window.

What OCR’s enforcement trajectory signals for 2026 and beyond

The Risk Analysis Initiative is not a one-cycle effort. OCR modeled it on the Right of Access Initiative launched in 2019, which produced more than 54 enforcement actions across three presidential administrations. The Risk Analysis Initiative reached 13 resolution agreements by April 2026, and OCR has formally announced it will expand the initiative in 2026 to cover risk management failures alongside risk analysis gaps. That expansion broadens the enforcement surface considerably. Organizations that conduct a risk analysis but fail to document remediation against identified risks now fall within scope.

The proposed Security Rule NPRM published in December 2024 signals where mandatory controls are heading: annual risk analysis requirements, mandatory MFA, mandatory encryption of ePHI at rest and in transit, regular vulnerability scanning, annual penetration testing, and 72-hour system restoration objectives after a breach. These are proposals, not yet final rules. But the enforcement record under the existing rule already treats organizations that lack these controls as high-priority investigation targets.

The NPRM also proposes a shift in how covered entities document their security programs. Under the proposed rule, technology asset inventories and network maps would become mandatory annual deliverables, not ad hoc documents produced when an assessor requests them. Incident response plans would require testing at least once every 12 months. Workforce training would need to cover cybersecurity awareness, going beyond the general HIPAA training most organizations currently provide. Organizations that build these practices into their operations now, before the rule is finalized, will have a meaningfully easier transition than those who wait for a compliance deadline to drive the work.

The enforcement data points to one conclusion. OCR does not primarily find organizations that made mistakes. It finds organizations that never built the program in the first place.

How Scrut helps healthcare organizations close these gaps

The violations OCR cites most consistently are not technical mysteries. They are program management failures. Risk analyses not conducted. Access not reviewed. Vendors not inventoried. Logs not monitored. Breach processes never rehearsed. Each one is preventable with the right operational infrastructure.

Scrut's continuous compliance platform automates the evidence collection and monitoring processes that let these gaps accumulate. Risk analysis workflows are structured, documented, and scheduled on a defined cadence. Access control reviews are tracked with completion records. BAA inventory is centralized and tied to vendor onboarding. Audit log reviews are automated with alert thresholds, removing the dependency on manual, intermittent review cycles.

For healthcare organizations and business associates managing HIPAA compliance, the gap between passing an initial audit and maintaining a defensible posture across years is an operational infrastructure problem. Scrut is built to close it.

See how Scrut helps healthcare organizations maintain continuous HIPAA compliance. Request a demo.

FAQs
What triggers an OCR HIPAA investigation?

OCR opens investigations through three main channels: formal complaints filed by individuals, compliance reviews initiated by OCR based on information received through media reports or referrals from other agencies, and breach notifications submitted through the HHS breach portal. A breach affecting 500 or more individuals triggers an automatic investigation. Smaller breaches reported on an annual basis may also attract scrutiny if patterns suggest systemic gaps. OCR also conducts proactive audits of covered entities and business associates, independent of any complaint or breach report.

How is a HIPAA risk analysis different from a risk assessment?

In HIPAA terminology, a risk analysis is the formal process of identifying potential risks and vulnerabilities to ePHI across all systems, workflows, and vendors. A risk assessment is often used as a broader term in general security practice. Under NIST 800-30 and HIPAA guidance, the two are closely aligned, but HIPAA specifically requires the risk analysis to be accurate and thorough, documented, and used as the basis for a risk management plan that addresses identified gaps. The risk management plan is the action component; the risk analysis is the diagnostic. Both are required, and OCR treats them as two distinct deliverables, not one.

Do business associates face the same HIPAA penalties as covered entities?

Yes. Since the 2013 Omnibus Rule, business associates are directly liable for HIPAA violations. OCR can investigate and penalize a business associate independently, without any action against the covered entity. The MMG Fusion settlement in March 2026 is an example: OCR pursued the software vendor directly for impermissible disclosure, inadequate risk analysis, and failure to notify affected covered entities. Business associates are also required to have their own HIPAA compliance programs, conduct their own risk analyses, and execute BAAs with their own subcontractors.

What should a covered entity do immediately after discovering a breach?

The 60-day notification clock starts at the point of discovery, not after the forensic investigation concludes. The immediate steps are to contain the incident, preserve evidence, begin a breach risk assessment to determine whether the exposure qualifies as a reportable breach under the four-factor test, and engage legal counsel. If the breach is reportable, notifications to affected individuals, OCR, and relevant media (for breaches over 500 in a state) must all be completed within 60 days of discovery. Business associates must notify the covered entity without unreasonable delay and within the timeframe specified in the BAA, which should be considerably shorter than 60 days.

How does OCR calculate HIPAA penalties?

OCR uses a four-tier penalty structure based on culpability. Tier 1 covers violations where the entity did not know and could not have known about the violation, with penalties from $100 to $50,000 per violation. Tier 2 covers reasonable cause, not willful neglect, with penalties from $1,000 to $50,000. Tier 3 covers willful neglect that was corrected within 30 days, with penalties from $10,000 to $50,000. Tier 4 covers willful neglect not corrected, with penalties from $50,000 up to $1.9 million per violation category per year. A single breach can involve violations across multiple categories, compounding the total exposure. Cooperation, demonstrated remediation, and a prior compliance record all influence where within each tier OCR lands.

Liked the post? Share on:
Choose risk-first compliance that’s always on, built for you.
Book a Demo
Book a Demo
Enjoyed this post? Let us know!

About Scrut Automation

Scrut Automation is a modern GRC platform designed to help fast-growing organizations simplify security, compliance, and risk management.

By combining continuous automation with expert guidance, Scrut reduces manual workloads, accelerates audit readiness, and empowers teams to scale their security posture confidently.

From HIPAA and SOC 2 to ISO 27001, GDPR, PCI, and beyond; Scrut helps teams achieve multi-framework compliance with ease.

Join our community and be the first to know about updates!

Subscribe
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Choose risk-first compliance that’s always on, built for you, and never in your way.

The Scrut Platform helps you move fast, stay compliant, and build securely from the start.

Book a Demo
Book a Demo