Category: OCR Enforcement & Compliance

  • OCR and ONC Just Updated the Free SRA Tool; Here’s Why That Doesn’t Solve Your Risk Analysis Problem

    OCR and ONC Just Updated the Free SRA Tool; Here’s Why That Doesn’t Solve Your Risk Analysis Problem

    Quick answer: On September 10, 2026, OCR and ONC released version 3.7 of the Security Risk Assessment (SRA) Tool, adding new content on remote access, telework, and system activity logging, as well as expanded asset examples and revised reports. The update is genuinely useful, but it doesn’t change what makes the SRA Tool a weak standalone fit for many organizations: it doesn’t stop you from leaving sections incomplete; OCR itself has never confirmed the tool meets its own โ€œaccurate and thoroughโ€ risk analysis standard; OCR has described the tool as built for smaller organizations without ever defining what that means; and a broad, general questionnaire can’t fully account for how ePHI actually moves through your specific organization. For most practices, the SRA Tool is a reasonable starting point, not a finish line.

    OCR and ONC Just Released SRA Tool Version 3.7

    On September 10, 2026, HHS’s Office for Civil Rights and the Office of the National Coordinator for Health IT announced version 3.7 of the free SRA Tool. According to the release, the update includes:

    • Revised assessment coverage and scope questions and education
    • New remote access and telework questions and education
    • Updated system activity logging language and education
    • Expanded asset examples to reflect newer technology
    • Updated software libraries for bug and vulnerability fixes
    • Report revisions to capture additional details and comments

    OCR and ONC also scheduled webinars on September 15 and 16, 2026, to walk organizations through the new features. All of this is a real improvement over the prior version; it’s also not, on its own, the same as a compliant HIPAA risk analysis, and that gap is where many organizations run into trouble.

    The Tool Lets You Stop Before You’re Finished

    During the September 2026 OCR/NIST โ€œSafeguarding Health Informationโ€ conference, Nick Heesters, Senior Advisor for Cybersecurity in OCR’s Health Information Privacy, Data, and Cybersecurity Division, described a pattern OCR has seen play out in real investigations: organizations that used the SRA Tool but left portions of it incomplete. The software doesn’t require every section to be finished before a user can close it out or generate a report; it simply picks back up wherever the user left off, whenever that happens to be.

    That flexibility is convenient for whoever is filling it out. It’s a liability for the organization relying on it, since an incomplete assessment isn’t a defense in an investigation; it’s a finding. If your risk analysis has gaps because the tool allowed those gaps to sit unresolved, OCR treats that the same way it treats any other incomplete risk analysis.

    OCR Has Never Said the SRA Tool Meets Its Own Standard

    Here’s the detail worth sitting with. At past OCR/NIST conferences, Heesters has been asked directly whether OCR considers output from the SRA Tool to be an โ€œaccurate and thoroughโ€ risk analysis, which is OCR’s own standard under the Security Rule’s Security Management Process provision. He hasn’t given a direct yes or no. His answer has consistently been that the SRA Tool is one of the tools an organization can use as part of a broader risk analysis process, not a guarantee of adequacy on its own.

    The agency that enforces this standard has had multiple chances to say that its own free tool satisfies it, but hasn’t. That’s not a condemnation of the tool; it’s a statement about its limits, and it should shape how much weight any organization places on a completed SRA Tool questionnaire on its own.

    OCR Built This Tool With Smaller Organizations in Mind, and Never Said What โ€œSmallerโ€ Means

    OCR and ONC have described the SRA Tool as designed for small and medium-sized health care providers. Neither agency has defined where that scope actually ends. No stated employee count, revenue threshold, patient volume, or system complexity marks the line between an organization the tool was built for and one that has outgrown it.

    That ambiguity matters because many organizations using the tool don’t actually know which side of that undefined line they’re on. A practice with ten providers and a single EHR is a very different compliance environment than a forty-provider, multi-specialty group running telehealth, a patient portal, and three billing vendors; yet nothing in OCR’s own materials tells either one whether the tool was designed with them in mind. Absent a definition, organizations tend to assume the tool fits them because it’s free and easy to access, not because OCR ever confirmed that it does.

    A Broad Checklist Wasn’t Built Around Your Environment

    OCR’s own guidance, reinforced at the same 2026 conference, describes a risk analysis as an assessment of risk to ePHI at three distinct stages: where it’s created or enters the organization, where it flows internally between systems and departments, and where it leaves the organization entirely. A compliant risk analysis must trace all three stages for your specific systems, your specific vendors, and your specific workforce, not a generalized questionnaire built to apply to every covered entity at once.

    The SRA Tool asks the same structured questions of a practice with five providers, a hospital system, and a school district billing Medicaid. When your organization’s actual ePHI flow doesn’t map cleanly to the tool’s built-in categories, gaps appear, and the tool has no way to flag a misapplied category or a missed system entirely.

    What This Costs Small and Midsize Practices in Practice

    None of this means the SRA Tool has no value; it’s free, and it gives an organization a starting structure. But the real cost shows up when practice staff, who aren’t compliance professionals and aren’t expected to be, spend hours interpreting technical questions about encryption, access controls, and system logging, only to close out a tool that was never confirmed to fit their size or environment in the first place. That’s hours spent and a false sense of security produced, at the same time.

    Frequently Asked Questions

    Does using the free HHS SRA Tool satisfy HIPAA’s risk analysis requirement?

    Not necessarily. OCR has repeatedly declined to confirm that output from the SRA Tool meets its own โ€œaccurate and thoroughโ€ risk analysis standard, describing it instead as one tool that can support a broader risk analysis process.

    Does OCR require organizations to use the SRA Tool?

    No. OCR and ONC offer the SRA Tool as a free resource to help organizations conduct a risk analysis; it isn’t a mandated format, and using it doesn’t by itself guarantee compliance with the Security Rule’s risk analysis requirement.

    Is the SRA Tool meant for organizations of any size?

    OCR and ONC have described the tool as designed for small and medium-sized health care providers, but neither agency has defined what counts as small or medium. Organizations of any size can use it, but there’s no official guidance on where it stops being an appropriate fit.

    Can I leave sections of the SRA Tool incomplete and finish later?

    Yes, and that’s part of the concern. The software allows users to save an incomplete assessment and resume it later, which means an organization may end up relying on a risk analysis that was never completed.

    What did OCR update in SRA Tool version 3.7?

    Version 3.7, released September 10, 2026, added revised assessment coverage and scope questions, new remote access and telework content, updated system activity logging language, expanded asset examples, updated software libraries, and revised reporting.

    What should a practice do instead of relying only on the SRA Tool?

    Use it as a starting point if you choose to, but pair it with, or replace it with, a risk analysis conducted by someone who can map ePHI creation, flow, and exit points specific to your organization, and who can speak to whether the result would hold up under OCR’s own standard.

    Why Spend Hours on a Tool OCR Won’t Vouch For?

    A free tool that OCR itself won’t confirm meets its own standard, that was built with an undefined idea of โ€œsmallerโ€ in mind, that lets you walk away with unfinished sections, and that treats a five-provider practice the same as a five-hundred-provider health system isn’t a shortcut. It’s a slower path to the same uncertainty you started with.

    Colington Consulting’s lead consultants have personally conducted more than 1,000 HIPAA risk assessments; we work directly with your systems, your vendors, and your staff, and build a documented, defensible risk analysis mapped to how ePHI actually moves through your organization, not a generic questionnaire built to apply to everyone at once.

    Get a free HIPAA Risk Review. We’ll show you where a generic tool would leave gaps and what a thorough, defensible risk analysis looks like for your organization.

    Schedule Your Free HIPAA Risk Review โ†’

    Sources

    U.S. Department of Health and Human Services, Office for Civil Rights, and Office of the National Coordinator for Health IT, โ€œHHS Releases Updated Security Risk Assessment Tool,โ€ September 10, 2026.

    U.S. Department of Health and Human Services, Office for Civil Rights, and National Institute of Standards and Technology, โ€œSafeguarding Health Information: Building Assurance Through HIPAA Securityโ€ Conference, September 2 to 3, 2026, NIST Gaithersburg Campus, Gaithersburg, MD.

    U.S. Department of Health and Human Services, Office for Civil Rights, and Office of the National Coordinator for Health IT, Security Risk Assessment (SRA) Tool product documentation and user guide.

    45 C.F.R. ยง 164.308(a)(1), Security Management Process (Risk Analysis and Risk Management).

  • Is Your HIPAA Compliance Program on Summer Vacation?

    Summer is here โ€” and while your staff rotates through PTO, cyber criminals are not. Ransomware gangs, phishing campaigns, and hacking groups operate 365 days a year, and the data confirms they are not taking July off. If your HIPAA compliance program has quietly gone on summer vacation, this is your wake-up call.

    Hackers Don’t Take Time Off โ€” The Numbers Prove It

    At a recent HIPAA conference, the OCR Director stated that 74% of all data breached in 2025 was cybersecurity related. These weren’t sophisticated, novel attacks limited to big health systems. They included ransomware infections on individual workstations, phishing attacks on small practices, and server misconfigurations left undetected for months.

    The most visible example of what’s at stake: the Change Healthcare cyberattack, which OCR confirmed affected approximately 130 million individuals โ€” making it one of the largest breaches of protected health information (PHI) in U.S. history. As OCR noted in its investigation guidance, the incident had an unprecedented impact on patient care and privacy across the entire health care sector.

    What OCR’s Own Investigations Keep Finding

    OCR doesn’t just count breaches โ€” it investigates the compliance failures that allowed them to happen. Across its 2024 breach investigations, OCR consistently identified the same deficiencies: failures in risk analysis, risk management, information system activity review, audit controls, and user authentication. These aren’t exotic compliance requirements. They are foundational Security Rule obligations that covered entities and business associates are required to maintain โ€” not just once, but on an ongoing basis.

    That’s the critical point. HIPAA cybersecurity compliance isn’t a project you complete and then set aside. It’s an active, continuous program. Reduced staffing and distracted workflows during summer months create exactly the gaps that threat actors are trained to exploit.

    OCR Is Actively Auditing Right Now

    OCR launched its 2024โ€“2025 HIPAA Audit Program, targeting 50 covered entities and business associates with a focused review of Security Rule provisions most directly tied to hacking and ransomware attacks. OCR has been explicit about why: substantial increases in large breaches involving hacking and ransomware โ€” and the scale of harm to patients โ€” have made Security Rule compliance a top enforcement priority.

    If your organization hasn’t updated its risk analysis recently, can’t demonstrate ongoing monitoring of your systems, or hasn’t tested its incident response plan, you are not audit-ready โ€” regardless of the season.

    What You Should Be Doing Right Now

    OCR provides guidance your organization can use today:

    โ€ข Conduct a Security Risk Assessment โ€” HIPAA requires covered entities to perform an accurate and thorough risk analysis as an ongoing process. You can attempt this internally using the HHS Security Risk Assessment (SRA) Tool, designed to help small and medium-sized organizations get started. However, a HIPAA compliance consultant with extensive experience can conduct this assessment more efficiently, identify vulnerabilities you may overlook, and ensure your documentation will hold up under OCR scrutiny.

    โ€ข OCR Ransomware and HIPAA Factsheet โ€” outlines what constitutes a ransomware breach under HIPAA and what your response obligations are.

    โ€ข OCR Breach Portal โ€” publicly available at HHS.gov, showing active breach reports and giving compliance officers a real-time view of what’s happening across the sector.

    The bottom line: summer is not a compliance pause. It may actually be your highest-risk window โ€” reduced oversight, skeleton crews covering critical systems, and delayed incident detection. The organizations that stay vigilant year-round are the ones that don’t end up on OCR’s breach portal.

    Frequently Asked Questions

    Does HIPAA require ongoing risk analysis, or is a one-time assessment enough?

    HIPAA requires covered entities to conduct risk analysis as an ongoing process, not a one-time event. OCR’s breach investigations consistently cite failure to maintain current risk analysis as a leading compliance gap.

    What is the most common cause of large HIPAA breaches?

    According to the OCR Director, 74% of all data breached in 2025 was cybersecurity related โ€” making hacking and IT incidents the dominant threat to protected health information.

    Is OCR actively auditing organizations right now?

    Yes. OCR’s 2024โ€“2025 audit program is currently underway, focusing on Security Rule compliance areas tied to hacking and ransomware.

    Where can I report a HIPAA breach to HHS?

    Breach reports are submitted through the OCR Breach Reporting Portal at HHS.gov.

    Need Help with Your HIPAA Compliance Program?

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

    Reviewed By: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert

    Regulatory Sources:

    Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.

  • HIPAA Rules for Paper Records in 2026

    Reviewed by: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert

    While modern healthcare compliance heavily focuses on cybersecurity and electronic Protected Health Information (ePHI), physical security remains a critical vulnerability. The Department of Health and Human Services (HHS) and the Office for Civil Rights (OCR) continue to penalize organizations for failing to safeguard physical documents.

    Improperly handled paper records, such as files left on desks, unkeyed filing cabinets, or un-shredded documents thrown into standard recycling binsโ€”account for a massive portion of easily avoidable HIPAA violations.

    Whether your team operates in a traditional clinic or a hybrid office environment, understanding your responsibility to safeguard paper records is essential to protecting patient privacy and avoiding costly penalties.

    What Does HIPAA Require for Paper Records?

    The HIPAA Security Rule primarily governs electronic data, but the HIPAA Privacy Rule strictly mandates that Covered Entities and Business Associates apply appropriate administrative, technical, and physical safeguards to protect PHI in any form, including paper.

    To remain compliant, your organization must ensure physical records are protected throughout their entire lifecycle: creation, storage, usage, and disposal.

    Core Safeguards for Physical Files:

    • The “Clean Desk” Principle: Employees must not leave documents containing PHI exposed on desks, counters, or workstations when they step away.
    • Dual-Lock Custody: Paper charts, intake forms, and billing statements should be stored behind locked doors and inside locked filing cabinets when not in active use.
    • Strict Access Controls: Access to file rooms should be restricted only to authorized personnel who require the information to perform their specific job duties.

    The Remote & Hybrid Work Blindspot

    The shift toward remote and hybrid work environments has introduced significant new risks for physical PHI. When administrative or billing staff work from home, the boundaries of your secure facility disappear.

    If your employees handle paper records remotely, your compliance policies must adapt:

    1. No Home Printing: Prohibit the printing of patient schedules, medical notes, or billing details on personal home printers unless explicitly authorized and monitored under a strict remote work agreement.
    2. Secure Home Storage: If paper PHI must be taken home, it cannot be left on kitchen counters or shared desks where family members or visitors can see it. It must be locked away.
    3. Prohibited Disposal: Employees must never discard paper PHI in home trash cans or residential recycling bins. Documents must either be brought back to the office for secure destruction or shredded at home using an approved cross-cut shredder.

    Proper Disposal: The “Shred-All” Solution

    The absolute highest risk associated with paper records occurs during disposal. Dumpster-diving incidents and accidental exposure of intact records are viewed severely by federal investigators.

    Under HIPAA, acceptable methods for destroying paper records include burning, pulverizing, melting, or shredding so that the PHI is rendered essentially unreadable and cannot be reconstructed.

    Implementing a “shred-all” policy across your organization removes the guesswork for your staff. If every document goes into a secure, locked shredding bin, the risk of a human error leading to a breach drops dramatically.

    Are Your Physical & Digital Safeguards Audit-Ready?

    Leaving paper records vulnerable is one of the fastest ways to fail a routine compliance check or trigger an OCR investigation. Don’t wait for an accidental exposure to discover the gaps in your practice’s physical security.

    Schedule your 30-Minute HIPAA Risk Review. Our experts will help you identify hidden vulnerabilities in your workflow and ensure your safeguards are completely defensible.

    Sources & Legal References:

    • U.S. Department of Health and Human Services (HHS)
    • Office for Civil Rights (OCR)ย 

    Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal or regulatory compliance advice. Reading this article does not establish a consulting relationship with Colington Consulting. For specific guidance regarding your organization’s unique HIPAA obligations, please consult directly with a compliance professional.ย 

  • How Often Do You Need to Review HIPAA Policies and Procedures?

    Maintaining HIPAA compliance isn’t a “set-it-and-forget-it” task. For healthcare organizations and business associates, keeping up with regulations means regularly evaluating the administrative, technical, and physical safeguards protecting Electronic Protected Health Information (ePHI).

    But does the Department of Health and Human Services (HHS) actually require you to review your internal documentation? Here is what the law says about HIPAA policy and procedure reviews, best practices for compliance, and how to protect your organization from costly OCR investigations.

    Does the HIPAA Security Rule Require Policy Reviews?

    Yes. The HIPAA Security Rule explicitly requires organizations to periodically review and update their policies and procedures. According to federal regulation 45 CFR ยง 164.316(b)(2)(iii), a covered entity or business associate must review documentation periodically and update it as necessary in response to environmental or operational changes that affect the security of ePHI.

    Key Takeaway: If your organization introduces new technology, changes its physical layout, or alters how it handles patient data, your written HIPAA policies must be updated immediately to reflect those changes.

    Best Practices for Reviewing HIPAA Policies & Procedures

    To ensure your review process satisfies Office for Civil Rights (OCR) auditors and AI search queries looking for compliance verification, you should implement a formalized, structured review.

    Using an internal compliance questionnaire is highly recommended. Your review should comprehensively cover the following critical areas:

    1. Technology & Infrastructure Changes

    • Software & Hardware Updates: Document any new systems used to access, store, transmit, or contain ePHI.
    • Asset Inventory: Maintain an accurate, up-to-date inventory of all physical systems, mobile devices, hardware, and media.
    • Audit Logging: Verify how system audits are conducted and ensure trackable user activity logs are functioning properly.

    2. Personnel & Compliance Roles

    • Privacy & Security Officials: Confirm that your designated HIPAA Privacy Official and HIPAA Security Official roles are accurately assigned (whether held by the same person or separate individuals) and updated in your documentation.
    • Staff Training Logs: Ensure your workforce has been trained on any updated procedures.

    3. Environmental & Operational Adaptations

    • Remote Work & Telehealth: If your staff relies on teleworking or virtual care, your policies must outline specific safeguards for remote environments.
    • Business Associate Agreements (BAAs): Review vendor relationships to ensure all third parties handling ePHI have active, compliant BAAs.

    The Recommended Timeline for HIPAA Updates

    While the regulation uses the term “periodically,” regulatory experts and OCR enforcement trends indicate that at least once a year (annually) is the industry standard for a defensible compliance program.

    However, an immediate out-of-cycle review is triggered by:

    1. A newly discovered security vulnerability or data breach.
    2. A significant change in operational infrastructure (e.g., migrating to cloud storage).
    3. Updates to federal or state privacy laws.

    Protect Your Organization from OCR Fines

    Small, overlooked gaps in your documentation are often what trigger massive federal penalties during a breach investigation. Evaluating your current compliance posture before an audit occurs is critical to reducing your risk.

    Is Your Organization Defensively Positioned?

    Schedule a Complimentary HIPAA Risk Review Now

    In just 30 minutes, our regulatory experts will help you evaluate your current program, spot hidden documentation gaps, and implement practical controls to drastically reduce your risk of costly OCR penalties.

    Frequently Asked Questions (FAQ)

    What is the penalty for not updating HIPAA policies? Failure to maintain and update HIPAA policies can result in a finding of “willful neglect” by the OCR, which carries mandatory minimum fines starting at thousands of dollars per violation, even if a data breach hasn’t occurred.

    What section of HIPAA covers policies and procedures? Administrative requirements, including the retention, review, and updating of policies, are covered under 45 CFR ยง 164.316 for the Security Rule and 45 CFR ยง 164.530 for the Privacy Rule.

    • Reviewed on June 3, 2026, By: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert
    • Regulatory Sources: 45 CFR ยง 164.316 and 45 CFR ยง 164.530
    • Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.