risk analysis initative

The Risk Analysis Initiative is driving HIPAA enforcement. But you can get ready and avoid penalties by tackling your risk profile today, and we can help.

If your organization hasn’t completed a risk analysis recently — or ever — the federal government is making it clear that this is no longer a paperwork exercise you can put off. The Office for Civil Rights (OCR) at the U.S. Department of Health and Human Services has spent the first half of 2026 steadily working through its Risk Analysis Initiative, and the message from every settlement is the same: a missing or incomplete risk analysis is now one of the fastest ways to turn a data breach into a six-figure penalty.

In April 2026 alone, OCR announced four settlements totaling more than $1.1 million to resolve ransomware-related breaches that together exposed the electronic protected health information (ePHI) of over 427,000 people. What makes this round of enforcement particularly useful to study is the variety. OCR didn’t go after one type of organization — it penalized two healthcare providers, a business associate, and a self-funded employee health plan, with breach sizes ranging from under 10,000 individuals to nearly a quarter million. In other words, no covered entity or business associate can assume that this enforcement priority doesn’t apply to them because of their size, sector, or role in the healthcare ecosystem.

The Common Thread: No Risk Analysis, No Defense

In each of the four April cases, OCR’s investigation turned up the same underlying failure.
Assured Imaging Affiliated Covered Entities — a medical imaging and screening provider based in Arizona and California — paid the largest penalty of the group, $375,000, after a 2020 ransomware attack exposed the ePHI of 244,813 individuals, including diagnoses, lab results, and treatment information. OCR found that Assured Imaging could not produce evidence that a risk analysis had ever been conducted, and that the organization also failed to notify affected individuals within the 60-day window required by the Breach Notification Rule.
Regional Women’s Health Group, doing business as Axia Women’s Health, agreed to pay $320,000 after a ransomware incident exposed the ePHI of 37,989 patients across its multi-state practice network. OCR’s investigation found that Axia had not performed a comprehensive and accurate risk analysis to identify risks and vulnerabilities to its ePHI, and the resulting corrective action plan also requires the organization to establish a process to evaluate how operational and environmental changes affect the security of its data going forward.
Star Group, L.P. Health Benefits Plan, the self-funded employee benefits plan of a Connecticut energy company, settled for $245,000 after a 2021 ransomware attack led to the theft of ePHI belonging to 9,316 plan members, including names, Social Security numbers, and claims data. This case is a useful reminder that health plans, not just clinical providers, are squarely within OCR’s enforcement scope, and that breach size has little bearing on whether an investigation results in a penalty.
Consociate, Inc., doing business as Consociate Health, a third-party administrator and business associate to several health plans, paid $225,000 after a phishing attack led to a six-month-long network compromise and the exposure of ePHI for 136,539 individuals, including Social Security numbers and financial account information. As a business associate rather than a covered entity, Consociate’s settlement emphasizes that OCR holds vendors to the same risk analysis standard as the providers and plans they serve.

Across all four cases, the violation cited most frequently and consistently was the same: failure to conduct an accurate and complete risk analysis. OCR Director Paula Stannard has been blunt about why this keeps showing up. Proactively implementing the Security Rule before a breach or an investigation occurs isn’t just the law, she’s noted — it’s also an organization’s best chance to prevent or limit the damage from a successful cyberattack.

These four cases bring OCR’s Risk Analysis Initiative total to 13 completed enforcement actions, and the agency has signaled that this trend will intensify. Beyond simply checking whether a risk analysis document exists, OCR is now scrutinizing whether organizations are actually acting on the findings of their risk analyses — meaning a stale or shelved risk analysis may offer little more protection than having none at all.

Enforcement Isn’t Just Coming from One Direction

It’s worth stepping back to remember that OCR is not the only body that can hold your organization accountable for an inadequate risk analysis. State Attorneys General in several states actively enforce HIPAA and equivalent state privacy laws, and several have pursued their own actions following data breaches, sometimes alongside OCR and sometimes independently.

And while HIPAA itself doesn’t create a private right of action, patients affected by a breach increasingly pursue litigation under state consumer protection, negligence, or data breach notification laws — and the discovery process in those cases routinely asks the same essential question OCR asks: did you have a current, accurate risk analysis in place?

For compliance officers managing with limited time and budget, this matters because it changes the cost-benefit calculation. A single risk analysis gap isn’t just exposure to one regulator. It’s exposure to three.

Enterprise-Wide Means Site-Specific

One detail in these settlements deserves more attention than it usually gets: a risk analysis has to be comprehensive across the entire organization, not just the corporate headquarters or a flagship location. Assured Imaging, for example, operates across multiple facilities, and OCR’s expectation — consistent across its enforcement actions — is that an enterprise-wide risk analysis means evaluating the risks and vulnerabilities at each individual site where ePHI is created, received, maintained, or transmitted.

If your organization has more than one office, clinic, or facility, a risk analysis completed at one location doesn’t satisfy your obligations at the others. Each site has its own physical safeguards, equipment, staff workflows, and vendor relationships — all of which need to be assessed individually.

Multi-site organizations that treat risk analysis as a single, organization-wide checkbox are leaving exactly the kind of gap that OCR’s investigators are trained to find.

You Don’t Need an Expensive Consultant to Get This Right

The good news is that completing a thorough, defensible risk analysis doesn’t require hiring an outside consulting firm for every site, every year. With the right framework, your own compliance staff can conduct a comprehensive internal risk analysis.

That’s the purpose behind The HIPAA E-Tool®. Our compliance software walks your team through every question OCR expects a risk analysis to answer, with step-by-step instructions for completing each one — whether you’re assessing a single office or coordinating risk analyses across a dozen locations. You don’t need specialized cybersecurity expertise to get started; you need a structured process and the right questions, and that’s exactly what we provide.

Given how consistently OCR, state regulators, and plaintiffs’ attorneys point to the same document as the foundation of HIPAA compliance, now is the time to confirm that yours is current, complete, and covers every site in your organization.

If it’s been a while since your last risk analysis — or if you’ve never been entirely confident it covered everything it should have — there’s no better moment to close that gap than before it becomes the subject of someone else’s investigation.

Visit thehipaaetool.com to see how The HIPAA E-Tool® can help your team complete a thorough, site-specific risk analysis.

Free HIPAA Checklist
What best describes you?