What OCR Enforcement Actions Teach About Risk Analysis
Anthem ($16M), Premera ($6.85M) and the pattern behind them: the same risk-analysis failures, cited over and over. What to fix before OCR notices.
The pattern
Read OCR's enforcement highlights and a pattern jumps out: the biggest settlements don't start with exotic attacks. They start with no risk analysis, or a bad one — then a breach exposes the gap, and the investigation finds the program was hollow. The breach gets the headlines; the missing risk analysis gets the penalty.
The big settlements
- Anthem — $16 million (2018). The largest HIPAA settlement to date, following a breach affecting nearly 79 million people. OCR's investigation cited failures including insufficient risk analysis.
- Premera Blue Cross — $6.85 million (2020). Breach affecting over 10 million individuals; OCR cited systemic noncompliance including risk-analysis failures.
- Excellus Health Plan — $5.1 million (2021). Breach affecting over 9 million; risk-analysis and risk-management failures among the cited violations.
Turn reading into quotes. Get scoped, comparable quotes from experienced HIPAA assessors — free, 2 minutes, no obligation.
Request quotesThe five recurring failures
- No enterprise-wide risk analysis. Partial analyses that miss systems, or analyses never performed at all.
- Stale analysis. A risk analysis from years ago, never refreshed as systems and threats changed.
- No remediation. Risks identified but never addressed — documented negligence, which is worse than ignorance.
- Missing encryption. Unencrypted laptops, portable media, and backups containing ePHI, year after year.
- No audit controls. No mechanism to record and examine access to ePHI — so breaches go undetected.
What "OCR-quality" actually means
OCR's risk-analysis guidance specifies nine elements: scope, data collection, threat and vulnerability identification, current security measures, likelihood and impact, risk levels, and documentation. An "OCR-quality" analysis covers all of them at the information-system level — granular enough that an investigator can follow your reasoning. Anything less is a checklist with aspirations.
The pre-audit play
Twelve weeks before any assessment or audit: refresh the risk analysis, verify encryption across ePHI stores, confirm BAAs are current, and close the remediation items the analysis flagged. Walk in with the program already trending up. Score yourself first with our readiness quiz.
Keep reading
There's No Such Thing as HIPAA Certification
HHS OCR does not certify anyone. What 'HIPAA certified' vendors are actually selling — and what real compliance looks like instead.
How to Choose a HIPAA Assessment Firm: 9 Questions to Ask
No government body accredits HIPAA assessors — so vetting is on you. The nine questions that separate real healthcare assessors from generalists.
HIPAA Risk Assessment Cost in 2026: What Organizations Actually Pay
The assessment fee is the smallest line item. A full first-year cost breakdown: analysis, readiness, program build, and staff time — with planning ranges.
Questions
What's the single highest-ROI compliance activity?
A current, thorough risk analysis. It's the required foundation, the most cited enforcement failure, and the document every other control decision references.
Can OCR audit us without a complaint?
Yes — OCR runs a proactive audit program covering covered entities and business associates, separate from complaint investigations.
Turn reading into quotes
Get scoped, comparable quotes from experienced HIPAA assessors — free, 2 minutes.
How it works: tell us once (4 questions, 2 min) → we match HIPAA assessors to your size, setting, and timeline → they send scoped quotes directly. Free, no obligation.