Skip to content
RiskTemplates · The Daily Brief Saturday, July 25, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Feature Data Privacy

HIPAA OCR Enforcement in 2025-2026: What 21 Settlements Reveal About Where Examiners Are Actually Looking

OCR ended 2025 with 21 HIPAA settlements and civil monetary penalties — the second highest annual total ever — driven by two active enforcement initiatives. Here's what the Warby Parker $1.5M penalty, the Risk Analysis expansion, and the Right of Access trend mean for every covered entity and business associate.

By Rebecca Leung · June 13, 2026 ·
Table of Contents

TL;DR

  • OCR ended 2025 with 21 HIPAA settlements and civil monetary penalties — second highest annual total ever — with 10 of those announced in the first five months of the year.
  • Two active enforcement initiatives are driving volume: Right of Access (54+ actions since 2019) and Risk Analysis (launched 2024, now expanding to risk management in 2026).
  • Warby Parker’s $1.5M civil money penalty in February 2025 is the largest recent enforcement action, citing Security Rule failures following a hacking incident — a reminder that any company holding ePHI faces OCR jurisdiction.
  • In 2026, OCR expanded the Risk Analysis Initiative: it now requires documented evidence that you acted on identified risks, not just that you identified them.

The HHS Office for Civil Rights ended 2025 with 21 HIPAA settlements and civil monetary penalties. The second highest annual total in the program’s history. Ten of those were announced by the end of May 2025 alone. The pace hasn’t slowed heading into 2026.

For covered entities and business associates — health plans, healthcare clearinghouses, healthcare providers, and every IT vendor, billing company, cloud service provider, HSA administrator, healthcare payment processor, and consulting firm that handles protected health information on their behalf — this trajectory carries a clear message: OCR’s two active enforcement initiatives are working, and 2026 expands their scope.

Here’s what the pattern of settlements actually tells you.

The Two Initiatives Driving 2025’s Record Pace

OCR’s enforcement output in 2025 concentrated around two structured programs:

Initiative 1: Right of Access (launched 2019)

OCR’s Right of Access enforcement has produced more than 54 financial penalties since 2019, making it the most consistently pursued HIPAA enforcement priority in the program’s recent history.

The legal standard: covered entities must provide individuals with access to their protected health information within 30 days of a request (with one available 30-day extension if the entity notifies the patient of the delay and the reason).

Concentra’s December 2025 settlement — $112,500 for failing to provide timely access — was the 54th action under this initiative. OHSU settled for $200,000 for untimely access in the same period. These are not large penalties by enforcement standards, but OCR has demonstrated it pursues them regardless of entity size or complexity.

The complaint-to-enforcement pipeline is well-established: patients know about the right, they exercise it, access is denied or delayed, and the OCR complaint follows. There’s no shortage of investigation triggers.

Initiative 2: Risk Analysis (launched 2024)

This is the newer initiative, and the one generating more enforcement volume in the 2025-2026 cycle. OCR’s Risk Analysis Initiative targets covered entities and business associates that have not conducted a comprehensive and accurate assessment of potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information, as required by 45 CFR 164.308(a)(1)(ii)(A).

Between January and August 2025 alone, OCR announced 16 resolution agreements citing risk analysis failures as a central finding. The pattern is consistent: a breach occurs (often ransomware), an investigation follows, and the investigation reveals the entity had never documented a risk analysis — or had one that was years out of date and hadn’t been updated after significant system changes. One small provider settled for $90,000 after a ransomware attack affecting 14,273 patients with the central finding being the absence of a prior risk analysis, not just the breach itself.

OCR announced its 11th and 12th Risk Analysis Initiative enforcement actions in late 2025 after a brief gap, confirming the initiative is ongoing.

The 2026 Expansion: Risk Management Now in Scope

The most significant 2026 development is OCR’s expansion of the Risk Analysis Initiative to include risk management.

This matters because many covered entities have a risk analysis document — a file that identifies risks to ePHI — but have not documented what they actually did to address those risks. That documentation gap was uncomfortable before. In 2026, it’s an enforcement exposure.

The legal requirement for risk management has always existed at 45 CFR 164.308(a)(1)(ii)(B): covered entities must implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level. OCR’s enforcement is now catching up to the full requirement.

What this means for compliance programs: having a risk analysis dated 18 months ago that identifies 40 ePHI risks, with no subsequent remediation documentation — no closed items, no treatment decisions, no management reviews — is exactly the gap the expanded initiative targets. OCR wants the loop closed.

Notable 2025-2026 Settlements: What the Cases Actually Found

The specifics matter. Here’s what the enforcement actions cited:

EntityAmountCore Findings
Warby Parker$1,500,000 CMPSecurity Rule violations; inadequate risk analysis; access controls; hacking investigation
OHSU$200,000 CMPRight of Access — untimely provision of PHI
Concentra$112,500 settlementRight of Access — untimely access; 54th initiative action
Small provider (ransomware)$90,000 settlementRisk analysis absent at time of ransomware attack on 14,273 patients
BST & Co.SettlementRisk analysis noncompliance
MMG Fusion, LLCSettlementRisk analysis noncompliance
Vision Upright MRISettlementBreach notification timing failures
BayCare Health SystemSettlementAccess controls and Security Rule

The Warby Parker case deserves attention because it establishes a point practitioners sometimes miss: Warby Parker is an eyewear company. Prescriptions and related patient records are PHI. OCR’s $1.5M civil money penalty for a hacking incident targeting that PHI makes clear that HIPAA enforcement applies to any entity holding ePHI — healthcare-adjacent companies, vision care, behavioral health apps, and fitness platforms with medical integrations are all within scope. “We’re not really a healthcare company” is not a HIPAA exemption.

Across the 2025-2026 enforcement actions, OCR’s resolution agreements consistently cite the same cluster of Security Rule failures: risk analysis not performed or not current, access controls not implemented, audit logging absent, breach notification delayed.

What the Right of Access Requirement Actually Demands

Right of Access sounds like a simple provision. The 54+ enforcement actions under this initiative suggest otherwise.

The common failure patterns across OCR cases:

Timing failures: Providing access in 35 or 40 days when the limit is 30 (or 60 with the extension and proper notice to the patient). OCR does not require evidence that the patient was harmed by the delay — late is late.

Incomplete responses: Providing access to some records but not all PHI requested. Covered entities using multiple EHR systems, paper records, or legacy databases frequently miss records during access requests because different systems require different access paths.

Improper format denials: Refusing to provide records in the format the patient specifically requested, if technically feasible. The right includes electronic access in the patient’s preferred format.

Fee overcharges: Charging more than the HIPAA-permitted cost of labor for producing electronic records, or charging retrieval fees that the rule doesn’t permit.

No intake process: Right of Access requests that arrive via fax, voicemail, patient portal message, or email without a formal intake workflow frequently fall through operational gaps and never get formally tracked.

The 2025 HIPAA Security Rule overhaul made major changes to technical safeguard requirements, but Right of Access is a separate administrative obligation that operates on its own compliance track.

What OCR’s Risk Analysis Standard Actually Requires

A HIPAA risk analysis is not a checkbox document. The Security Rule standard from 45 CFR 164.308(a)(1) and HHS guidance establishes what “comprehensive and thorough” actually means:

  • Complete ePHI inventory: Identify all ePHI the entity creates, receives, maintains, or transmits — across all systems, devices, media, and locations, including cloud services, portable devices, and legacy systems
  • Threat and vulnerability identification: Assess reasonably anticipated threats to ePHI, including workforce threats, environmental threats, and technical vulnerabilities
  • Likelihood and impact assessment: Estimate the probability that a threat will exploit a vulnerability and the resulting impact on ePHI confidentiality, integrity, and availability
  • Risk level determination: Document a risk level for each identified threat/vulnerability combination
  • Repeatability: Conduct a new risk analysis (or update the existing one) after significant environmental or operational changes — new systems, mergers, cloud migrations, new product lines, workforce changes

The gap that generates most enforcement cases: organizations that conducted a risk analysis during initial HIPAA compliance implementation but haven’t updated it since. A risk analysis from 2021 is not a current risk analysis for a 2025 OCR examination if the organization has migrated to cloud, added remote work at scale, or deployed new clinical or billing systems since then.

For ransomware incidents specifically, the enforcement pattern is established: a ransomware attack occurs, the investigation reveals the entity lacked a current documented risk analysis, and OCR cites both the breach and the documentation failure as separate violations. A strong ransomware incident response gets you through the containment and recovery. The pre-incident documentation posture determines your enforcement exposure.

What Corrective Action Plans Are Requiring in 2025-2026

OCR’s resolution agreements typically combine a financial penalty with a multi-year Corrective Action Plan (CAP). The 2025-2026 CAP requirements reveal what OCR considers minimum program components:

  • Risk analysis completion: Typically required within 90–180 days of the settlement date
  • Risk management plan: A written plan documenting how identified risks will be addressed, with timelines and responsible parties — this is the 2026 addition
  • Policies and procedures update: Revised HIPAA Security Rule and Privacy Rule policies
  • Workforce training: HIPAA-compliant training for all workforce members within 90 days
  • Progress reporting: Semi-annual reports to OCR for 2–3 years following the settlement
  • Incident review: Post-incident analysis with documented findings and corrective steps

The multi-year monitoring period signals that OCR is not treating these as one-time compliance failures — it’s treating them as program maturity deficits that require sustained oversight.

The Practical Compliance Priority List

Based on what the 2025 enforcement pattern shows, here’s where to focus:

Right of Access (fix first if you don’t have a documented workflow):

  1. Define a formal intake process that captures requests regardless of how they arrive
  2. Assign ownership and a tracking mechanism (date received, format requested, response due date)
  3. Test the end-to-end process with a real request — time it, measure gaps
  4. Document the fee schedule and confirm it matches HIPAA-permitted charges

Risk Analysis (refresh if yours is more than 12 months old):

  1. Update the ePHI inventory to reflect current systems, cloud services, and any new integrations
  2. Reassess threats and vulnerabilities given current infrastructure
  3. Re-score risk levels with updated information
  4. Document who reviewed and approved the updated analysis and when

Risk Management (new 2026 requirement):

  1. For each identified risk at High or Critical level, document what control or remediation was implemented
  2. Record completion evidence: implementation date, responsible party, validation method
  3. Establish a regular review cycle (at minimum annually) to assess whether prior remediation remains effective

For covered entities and business associates that need a privacy documentation framework covering HIPAA requirements alongside 19 state privacy laws, GLBA, consumer rights request workflows, and data processing agreement templates, the Data Privacy Compliance Kit provides templates for each domain — available for $69.

So What?

OCR’s enforcement trajectory — 21 settlements in 2025, expanded scope in 2026 — isn’t a blip. It’s a sustained program with specific, documentable targets: Right of Access within 30 days, current risk analysis, and now documented risk management.

The entities settling are not all large healthcare systems. They include vision care companies, small providers, and non-traditional healthcare businesses. The consistent finding across cases isn’t sophisticated security failures — it’s absent documentation that should have been standard program infrastructure.

Three questions to check before your next OCR compliance review:

  1. Is your risk analysis current — updated within the last 12 months and after any material system change?
  2. For your last risk analysis cycle, can you show what you did with the identified risks — not just that you identified them?
  3. Do you have a documented Right of Access intake process with time-tracking from request receipt to response delivery?

If the answer to any of those is “no,” that’s an open gap. For breach notification obligations — including the HIPAA 60-day breach notification standard alongside all 50 state breach notification deadlines — see State Breach Notification Laws: 50-State Comparison and How to Track Deadlines.


Sources: HHS OCR Resolution Agreements · Recent HIPAA Violation Cases: 2026 Update · 2025 HIPAA Enforcement Tally · HIPAA Penalties 2026 · HHS OCR Concentra Settlement

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

How many HIPAA enforcement actions did OCR bring in 2025?
OCR ended 2025 with 21 settlements and civil monetary penalties — the second highest annual total in the program's history. Ten of those were announced by the end of May 2025 alone, driven largely by the Risk Analysis enforcement initiative that launched in 2024.
What is OCR's Risk Analysis enforcement initiative?
Launched in 2024, the Risk Analysis Initiative targets covered entities and business associates that have not conducted a comprehensive and accurate risk analysis of potential risks to ePHI, as required by 45 CFR 164.308(a)(1)(ii)(A). In 2026, OCR expanded the initiative to also require documented risk management — meaning it's not enough to identify risks; entities must show they acted on them.
What are the most common HIPAA violations leading to OCR penalties?
The two largest areas are Right of Access failures (not providing patients with timely access to their PHI within 30 days) and risk analysis failures (not conducting a comprehensive security risk assessment). Secondary priorities include timely breach notification, workforce training, access controls, and audit logging.
What was the Warby Parker HIPAA penalty about?
OCR issued a $1.5 million civil money penalty against Warby Parker on February 20, 2025, arising from a cybersecurity hacking investigation. OCR cited Security Rule violations including inadequate risk analysis and insufficient access controls. The case illustrates that non-traditional healthcare companies holding ePHI face the same enforcement exposure as providers.
Can a small covered entity face a significant HIPAA penalty?
Yes. OCR penalized a small provider $90,000 after a ransomware attack affecting 14,273 patients revealed the entity had not conducted a prior risk analysis. OCR treats the absence of required documentation as a separate violation from the breach itself — the penalty applies to the process failure, not just the incident outcome.
What does the 2026 Risk Analysis Initiative expansion mean for compliance programs?
OCR is now looking for documented evidence that identified risks were acted upon — not just that a risk analysis was conducted. Covered entities with a risk analysis on file but no documented remediation plan, remediation completion records, or ongoing risk management process face increased enforcement exposure in 2026 examinations.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Data Privacy Compliance Kit

Multi-state privacy compliance templates covering 19 state laws plus GLBA and CCPA.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.