What triggers a HIPAA audit or investigation
Office for Civil Rights (OCR) investigates practices through three channels: patient complaints, breach reports, and enforcement initiatives. How each works and how to lower your risk.
By CoreFolio
8-minute read
An investigation by the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) is not random. It follows from specific triggers. Understanding those triggers — and what each one sets in motion — is more useful than a general instruction to “be HIPAA compliant.”
OCR investigates covered entities through three primary channels: patient and workforce complaints, breach notification reports, and proactive compliance reviews. Each has its own mechanics, and each can result in the same outcome: a formal investigation with document requests, potential corrective action, and financial settlement.
Channel 1: patient and workforce complaints
Under 45 CFR § 160.306, any person who believes a covered entity has violated a HIPAA rule may file a complaint with OCR. Complaints are submitted through the OCR complaint portal at hhs.gov/ocr or by mail. OCR receives tens of thousands of complaints per year.
What OCR does with a complaint:
OCR screens complaints for jurisdictional requirements — the complaint must involve a covered entity or business associate, must be filed within 180 days of the alleged violation (unless OCR waives this for good cause), and must describe a potential HIPAA violation.
Complaints that pass screening may be resolved through:
- Technical assistance — informal guidance without a finding of violation, for first-time minor issues
- Early dispute resolution — the covered entity agrees to take corrective action voluntarily
- Formal investigation — OCR opens a compliance review with document requests and findings
Common complaint categories in small-practice investigations:
- Impermissible disclosures of PHI without patient authorization (disclosures to family members, employers, or unauthorized parties)
- Denial or delay of patient right of access to records (OCR has brought 54 enforcement actions under its Right of Access Initiative, with settlements ranging from $3,500 to $240,000)
- Insufficient safeguards resulting in an unauthorized person viewing ePHI (workstation positioning, shared login credentials)
- Retaliation against a patient or workforce member for filing a HIPAA complaint (a separate violation under 45 CFR § 164.530(g))
Channel 2: breach notification reports
Under the Breach Notification Rule (45 CFR § 164.408), covered entities must report breaches to HHS:
- Breaches affecting 500 or more individuals: within 60 days of discovery
- Breaches affecting fewer than 500 individuals: in an annual log submitted within 60 days after the end of the calendar year
Both categories of breach reports are reviewed by OCR. Larger breaches appear immediately on the HHS “Wall of Shame” — the public breach portal at ocrportal.hhs.gov — and frequently prompt OCR to open an investigation.
What makes a breach report more likely to trigger investigation:
- Large number of affected individuals
- Nature of the incident (ransomware attacks, hacking, theft of unencrypted devices receive heightened scrutiny)
- Evidence of systemic failure (such as multiple similar breaches from the same covered entity over time)
- The covered entity’s response and documentation quality
Small breaches and the annual log: A covered entity reporting a handful of small incidents in its annual log may not trigger immediate investigation. But a pattern of repeated small breaches — particularly of the same type — can indicate systemic compliance failures that draw OCR attention.
The April 2026 four-practice ransomware settlement (combined $1,165,000 across four entities) illustrates how breach notifications can lead directly to enforcement: all four practices had reported ransomware incidents; OCR investigated and found missing or inadequate risk analyses in each case.
Channel 3: proactive enforcement initiatives
OCR has authority under 45 CFR § 160.308 to conduct compliance reviews on its own initiative, without a complaint or breach report. OCR has used this authority to target specific compliance categories with dedicated enforcement programs.
The Risk Analysis Initiative (launched October 2024)
OCR’s most active proactive program as of 2026 is the Risk Analysis Initiative, which selects covered entities for compliance reviews specifically around 45 CFR § 164.308(a)(1) — the requirement to conduct an accurate and thorough risk analysis.
As of April 23, 2026, OCR reported 13 completed investigations under the Risk Analysis Initiative, with settlements ranging from $5,000 to $375,000; several closely related risk-analysis settlements were resolved in the same period under the Security, Privacy, and Breach Notification Rules.1 Covered entities selected for the initiative have included small practices across multiple specialties, including neurology, substance use disorder treatment, and behavioral health.
OCR’s 2016–2017 audit found that only 14 percent of covered entities were substantially meeting their risk analysis obligations.2 The Risk Analysis Initiative is OCR’s response to that finding.
The Right of Access Initiative (launched 2019, ongoing)
OCR launched a dedicated enforcement initiative targeting covered entities that deny or delay patients’ right to access their records under 45 CFR § 164.524. As of late 2025, OCR had brought 54 enforcement actions under this initiative. Settlements have ranged from $3,500 (a small practice that provided records after OCR intervention) to $240,000 (Memorial Hermann Health System).3 Concentra, Inc. settled in December 2025 for $112,500, marking the initiative’s 54th enforcement action.4
The HIPAA Audit Program (periodic)
Under 45 CFR § 160.308, HHS may conduct audits to assess compliance across covered entities and business associates. The most recent completed audit program ran in 2016–2017; in late 2024 OCR launched a new round of audits reviewing 50 covered entities’ and business associates’ compliance with Security Rule provisions most relevant to hacking and ransomware.5
What happens after OCR opens an investigation
An OCR investigation begins with a written notification to the covered entity. The entity typically has 30 days to respond with documentation — the risk analysis, risk management plan, workforce training records, business associate agreements, policies and procedures, and incident logs are standard requests.
OCR reviews the documentation and may request additional materials or schedule a site visit. Investigations typically close in one of four ways:
- No violation found — the covered entity’s documentation demonstrates compliance; the case is closed
- Technical assistance — OCR identifies gaps but resolves through informal guidance without a penalty
- Resolution agreement — a formal settlement document with a financial penalty and a corrective action plan (CAP). The CAP typically requires completing a risk analysis, developing a risk management plan, implementing workforce training, and submitting compliance reports to OCR for a monitoring period (often two years)
- Civil money penalties — for serious or willful violations, OCR may impose penalties without a settlement agreement; the maximum annual penalty per violation category is $2,190,294 (effective January 28, 2026, indexed for inflation).6
How to reduce investigation risk
The practices that fare best in OCR investigations are not necessarily the ones with the most sophisticated security. They are the ones with documentation that demonstrates they have assessed their risks and taken reasonable and appropriate action.
The minimum risk-reduction set:
- A current risk analysis — the primary finding in every enforcement action; it must be dated within the past 12 months or updated after material environmental changes
- A written risk management plan — with action items, timelines, and responsible parties
- Prompt patient records access — respond to records requests within 30 days (or 60 days with a documented 30-day extension)
- A written security incident response plan — so your practice has a procedure ready before an incident occurs
- A breach log — maintained for all incidents, including those that did not rise to the level of reportable breach
- Workforce training records — documentation that every staff member has been trained, when, and on what
A covered entity that can produce these documents is in a materially better position than one that cannot — regardless of the investigation channel that initiated the inquiry.
Sources
Footnotes
-
U.S. Department of Health and Human Services, Office for Civil Rights, HHS Office for Civil Rights Settles Four HIPAA Ransomware Cybersecurity Investigations (April 2026), which reported 13 completed investigations under the Risk Analysis Initiative, with settlements ranging from $5,000 to $375,000. https://www.hhs.gov/press-room/ocr-settles-four-ransomware-investigations.html See also the OCR Risk Analysis Initiative record. ↩
-
U.S. Department of Health and Human Services, Office for Civil Rights, 2016–2017 HIPAA Audits Industry Report (December 2020). Found only 14 percent of audited covered entities (and 17 percent of business associates) were substantially fulfilling their risk-analysis responsibilities. https://www.hhs.gov/sites/default/files/hipaa-audits-industry-report.pdf ↩
-
U.S. Department of Health and Human Services, Office for Civil Rights, resolution agreements. The largest Right of Access settlement to date is Memorial Hermann Health System ($240,000, 2022); the smallest is $3,500. https://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/agreements/ ↩
-
U.S. Department of Health and Human Services, HHS’ Office for Civil Rights Settles HIPAA Right of Access Investigation with Concentra, Inc. (Dec. 16, 2025). Concentra agreed to pay $112,500; OCR’s 54th Right of Access enforcement action. https://www.hhs.gov/press-room/ocr-settles-with-concentra.html ↩
-
U.S. Department of Health and Human Services, Office for Civil Rights, OCR’s HIPAA Audit Program — 2024–2025 HIPAA Audits. OCR is reviewing 50 covered entities’ and business associates’ compliance with Security Rule provisions most relevant to hacking and ransomware. https://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/audit/index.html ↩
-
U.S. Department of Health and Human Services, Annual Civil Monetary Penalties Inflation Adjustment, 45 CFR Part 102, 91 Fed. Reg. 3665 (Jan. 28, 2026). Sets the maximum annual penalty per identical provision at $2,190,294, effective January 28, 2026. https://www.govinfo.gov/content/pkg/FR-2026-01-28/html/2026-01688.htm ↩