Quick answer: At the OCR/NIST โSafeguarding Health Informationโ conference held September 2 to 3, 2026, in Gaithersburg, Maryland, HHS’s Office for Civil Rights delivered a consistent message across sessions: enforcement is not slowing down; risk analyses remain the most commonly cited deficiency because they are still inaccurate or incomplete; and many organizations still lack the documented policies and procedures needed to turn a risk analysis into an actual risk management program. OCR was direct on one point in particular: organizations should not wait for a breach, or a completed OCR investigation, before conducting a compliant risk analysis.
Why This Conference Matters for Compliance Programs
Each year, OCR and NIST’s Information Technology Laboratory co-host this conference to walk through where enforcement is headed and where organizations continue to fall short. This year’s agenda, spanning two full days, included briefings from OCR’s Director, threat intelligence updates from the Health Information Sharing and Analysis Center, and a dedicated OCR track on the Health Information Privacy, Data, and Cybersecurity Division’s own enforcement data.
For compliance teams that could not attend, the sessions functioned less like a lecture and more like a preview of what OCR expects to see when it opens the next investigation, whether that investigation starts with a breach report or a routine complaint.
Three themes ran through nearly every OCR-led session.
1. Enforcement Is Not Slowing Down
OCR used its own numbers to make the point directly. As of this year’s conference, OCR reported 21 completed ransomware investigations and 14 completed investigations under its Risk Analysis Enforcement Initiative; separately, its Right of Access Initiative, focused on individuals being denied timely access to their own health records, has produced 55 completed enforcement actions to date, with a newly stated focus on parent and personal representative access requests.
The shift in breach data helps explain where that enforcement attention is concentrated. Comparing OCR’s historical breach portal data, September 2009 through December 2025, against the first seven months of 2026:
- Hacking and IT incidents grew from 52 percent of reported large breaches to 75 percent.
- Network servers, as the breach location, grew from 39 percent to 68 percent.
- Theft, once 18 percent of reported breaches, has fallen to roughly 1 percent.
- Physical causes, such as paper records and lost laptops, have both dropped to a small share of the total.
In short, OCR’s own data show breaches are concentrated almost entirely in network-based, hacking-related incidents, and its enforcement priorities follow that data. Organizations that assume a strong physical security posture covers their exposure are missing where the actual risk, and the actual enforcement attention, now sits.
2. OCR Still Finds Risk Analyses Inaccurate and Incomplete
If OCR repeated one message more than any other, it was this: a risk analysis is requested in every Security Rule investigation OCR conducts, and it remains one of the most commonly deficient documents organizations produce.
OCR drew a specific distinction that trips up many compliance programs: a gap analysis is not the same as a risk analysis. A gap analysis compares current practices against a checklist or a set of standards. A risk analysis, as required under the Security Rule’s Security Management Process standard, is a more rigorous exercise; it requires organizations to assess risks to all electronic protected health information at every stage in which that information exists within the organization, with enough specificity to drive decisions.
OCR’s guidance broke this down into three stages that a thorough risk analysis has to cover:
- Where ePHI is created or enters the organization: file transmissions and uploads, manual data entry or edits to existing ePHI, and lab results or images coming in from outside systems.
- Where ePHI flows within the organization: movement into EHR systems, between clinical and other departments, through applications such as office productivity tools, web and mobile platforms, and remote access, and across infrastructure such as backups and system logs.
- Where ePHI leaves the organization: email, fax, and file transfer applications, collaboration tools, and equipment disposal.
An organization that has assessed risk at only one of these three stages, most commonly the point where ePHI enters or lives in the primary EHR, has not completed the kind of accurate and thorough risk analysis the Security Rule actually requires. This is very likely why risk analysis deficiencies remain the most cited finding across OCR’s enforcement actions.
3. Organizations Still Lack Comprehensive Policies and Procedures
The third theme is closely tied to the second. OCR was clear that a risk analysis is not the finish line; it is meant to be a direct input into an organization’s risk management process, used to develop corrective actions for each identified risk and to guide the implementation of security measures that reduce risk to a reasonable and appropriate level while protecting the confidentiality, integrity, and availability of ePHI.
In practice, this is where many compliance programs stall. A risk analysis is completed, findings are documented, and then the corresponding policies, procedures, and corrective action plans are never built, updated, or tied back to what the risk analysis actually found. The Right of Access Initiative is a clear example of this gap in action: individuals have a right under the Privacy Rule to timely access to their own health records, generally within 30 days, with the possibility of one 30-day extension, and at a reasonable, cost-based fee. OCR continues to receive a high volume of complaints alleging denial of access, which points less to organizations being unaware of the rule and more to access request procedures that are not documented, not followed consistently, or not updated to reflect current staff and systems.
The pattern OCR described is consistent: a risk analysis without a connected risk management program, and policies without a documented, current process behind them, are both incomplete compliance postures, even when each piece looks reasonable on its own.
What OCR Wants Organizations to Do Right Now
OCR’s message on timing was direct, and it is worth stating exactly as presented: organizations should not wait for a breach, or for a completed OCR investigation, before conducting a compliant risk analysis. Waiting is, itself, the exposure.
OCR also pointed attendees to its own risk analysis resources, including a risk analysis explainer video, the Security Risk Assessment (SRA) Tool, and ongoing guidance and cybersecurity newsletters, all built to help organizations complete a risk analysis that meets the Security Rule’s standard rather than a lighter gap assessment.
Organizations must also notify affected individuals of a breach no later than 60 calendar days after discovery, a deadline that does not shift based on the organization’s size or complexity.
Frequently Asked Questions
Is OCR’s HIPAA enforcement slowing down in 2026?
No. OCR reported 21 completed ransomware investigations, 14 completed Risk Analysis Enforcement Initiative investigations, and 55 completed Right of Access enforcement actions as of its 2026 conference, and its breach data shows hacking and network server incidents making up a growing share of reported breaches.
Is a gap analysis the same as a HIPAA risk analysis?
No. OCR was explicit that a gap analysis, which compares current practices to a checklist, does not meet the Security Rule’s risk analysis requirement. A compliant risk analysis assesses risk to all ePHI as it is created, as it flows through the organization, and as it leaves the organization.
Does OCR require a risk analysis for every investigation?
Yes. OCR stated that it requests a risk analysis in every Security Rule investigation it conducts, which makes an outdated or incomplete risk analysis one of the most common findings across enforcement actions.
What is OCR’s Right of Access Initiative?
It is an enforcement initiative focused on individuals being denied timely access to their own health records. The HIPAA Privacy Rule requires access generally within 30 days, with one possible 30-day extension, at a reasonable, cost-based fee; OCR has completed 55 enforcement actions under this initiative and has signaled a new focus on parent and personal representative access.
Should organizations wait for a breach before doing a risk analysis?
No. OCR was clear on this point: organizations should not wait for a breach or a completed OCR investigation before conducting a compliant risk analysis.
Not Sure Your Risk Analysis Would Hold Up to OCR’s Standard? Colington Consulting Can Help You Find Out
OCR was clear that a risk analysis needs to cover ePHI at every stage it exists in your organization, feed directly into a documented risk management program, and stay current, not sit as a one-time project. Colington Consulting works directly with covered entities and business associates to build and maintain the accurate, thorough risk analysis and related policies and procedures OCR expects to see before an investigation starts.
Get a free HIPAA Risk Review. We will help you see exactly where your risk analysis and policies and procedures stand relative to what OCR is actually enforcing, and show you where to focus first.
Schedule Your Free HIPAA Risk Review โ
Sources
U.S. Department of Health and Human Services, Office for Civil Rights, and National Institute of Standards and Technology, โSafeguarding Health Information: Building Assurance Through HIPAA Securityโ Conference, September 2 to 3, 2026, NIST Gaithersburg Campus, Gaithersburg, MD.
U.S. Department of Health and Human Services, Office for Civil Rights, conference session materials: Risk Management; Key Takeaways; Right of Access Initiative; Risk Analysis: Accurate and Thorough.
U.S. Department of Health and Human Services, Office for Civil Rights, HIPAA Breach Portal data, breaches by type and location of breach, September 23, 2009 through July 31, 2026.
45 C.F.R. ยง 164.308(a)(1) โ Security Management Process (Risk Analysis and Risk Management).
45 C.F.R. ยง 164.524 โ Right of Access.

