OCR Is Watching: The Risk Analysis Initiative & What It Means for Your Practice
When HHS's Office for Civil Rights launched its Risk Analysis Initiative in fall 2024, some in the healthcare compliance community treated it as another periodic enforcement push, the kind that generates a few headlines and then fades. Twelve-plus enforcement actions later, it is clear that OCR is not letting up. The Risk Analysis Initiative is a sustained, targeted campaign, and the practices caught in its crosshairs have one thing in common: they couldn't prove they had done an adequate Security Risk Assessment.
Understanding what OCR is looking for and how enforcement has evolved is essential context for any practice navigating the 2026 MIPS and HIPAA landscape.
WHAT THE RISK ANALYSIS INITIATIVE IS
OCR formally launched the Risk Analysis Initiative as a dedicated enforcement program focused on organizations that had failed to conduct, or failed to document, an adequate security risk analysis under the HIPAA Security Rule. The initiative was informed by years of OCR breach investigations, which consistently revealed that inadequate risk analysis was among the most common root causes of large-scale breaches.
The message from OCR was direct: the Security Rule's risk analysis requirement is not aspirational guidance. It is a legal obligation, and OCR will enforce it.
THE ENFORCEMENT RECORD
By early 2026, OCR had announced more than a dozen enforcement actions under the Risk Analysis Initiative. Penalties have ranged from tens of thousands of dollars for smaller entities to settlements exceeding a million dollars for larger covered entities. Critically, OCR has pursued both covered entities and business associates; the scope of the initiative is not limited to hospitals or health systems. Medical practices, behavioral health providers, specialty clinics, and other smaller organizations have all been named.
In each case, OCR's investigation found one or more of the following:
- No formal risk analysis had been conducted, or the last one was years old
- The risk analysis was incomplete; it didn't cover all systems processing ePHI, or it didn't identify specific threats and vulnerabilities
- The organization had identified risks but had no documented risk management plan or evidence of remediation
- Documentation was inadequate to demonstrate what had been done and when
THE SHIFT FROM "DID YOU DO IT" TO "PROVE IT"
This is the most important enforcement trend for 2026. OCR has moved beyond simply asking whether a risk analysis was conducted. Investigators now expect organizations to produce evidence: the actual assessment documents, risk registers, remediation plans, implementation records, and supporting policies.
A verbal assurance that "we handle security" does not pass an OCR audit. A generically formatted template with no organization-specific content does not pass. What passes is contemporaneous, specific documentation showing that your practice assessed its actual systems and data flows, identified its actual risks, and took actual steps to address them with dates, responsible parties, and outcomes.
OCR'S 2026 ENFORCEMENT PRIORITIES
Based on enforcement actions and OCR's January 2026 Cybersecurity Newsletter, the office's current focus areas include:
- Enterprise-wide risk analysis quality: Does the assessment cover every system that touches ePHI, including cloud services, mobile devices, and third-party applications?
- Risk management follow-through: Is there a documented, active plan to remediate identified vulnerabilities? Is it being executed?
- Technical controls: Specifically: encryption, MFA, audit logging, patch management, and access control review
- Business associate risk: Has the covered entity assessed the risks posed by its BA relationships, and obtained verification of BA compliance?
- Incident response readiness: Does the organization have a tested, documented plan?
THE CONNECTION TO MIPS
The 2026 MIPS dual attestation requirement - confirm you conducted an SRA, confirm you acted on it - is not coincidental. CMS and OCR are aligned on the standard. What satisfies OCR's enforcement expectations is also what satisfies CMS's attestation requirements. The two programs are converging on the same definition of a compliant security program.
Practices that complete a thorough, documented SRA with a real risk management component are not just protecting their MIPS score. They are building the evidentiary record that would protect them in an OCR investigation.
WHAT THIS MEANS FOR YOUR PRACTICE
If your most recent risk assessment is more than 12 months old, you are already out of compliance with what OCR expects and out of compliance with the 2026 MIPS requirement. If your assessment was done but the findings sit in a report with no remediation activity, you are exposed on both fronts.
The good news: OCR has repeatedly noted in its enforcement resolutions that organizations that get ahead of compliance that demonstrate proactive, good-faith efforts; fare better than those that ignore the requirement until an incident forces the issue.
December 31 is the MIPS deadline. There is no equivalent OCR deadline, but there is a very real risk that the next time OCR comes knocking, the question will be whether you acted in 2026 when you had the chance.
Chirpy Bird's full-service SRA produces exactly the documentation OCR auditors expect: a comprehensive assessment of your ePHI environment, a detailed issue report, prioritized remediation recommendations, and a complete audit-ready documentation package. Our DIY tool gives practices the same rigorous framework with expert-built guidance, at their own pace. Both options deliver the reports that protect you, whether the question comes from CMS or OCR. Get protected before December 31.