Category: OCR Enforcement & Compliance

  • Is Your HIPAA Compliance Program on Summer Vacation?

    Summer is here โ€” and while your staff rotates through PTO, cyber criminals are not. Ransomware gangs, phishing campaigns, and hacking groups operate 365 days a year, and the data confirms they are not taking July off. If your HIPAA compliance program has quietly gone on summer vacation, this is your wake-up call.

    Hackers Don’t Take Time Off โ€” The Numbers Prove It

    At a recent HIPAA conference, the OCR Director stated that 74% of all data breached in 2025 was cybersecurity related. These weren’t sophisticated, novel attacks limited to big health systems. They included ransomware infections on individual workstations, phishing attacks on small practices, and server misconfigurations left undetected for months.

    The most visible example of what’s at stake: the Change Healthcare cyberattack, which OCR confirmed affected approximately 130 million individuals โ€” making it one of the largest breaches of protected health information (PHI) in U.S. history. As OCR noted in its investigation guidance, the incident had an unprecedented impact on patient care and privacy across the entire health care sector.

    What OCR’s Own Investigations Keep Finding

    OCR doesn’t just count breaches โ€” it investigates the compliance failures that allowed them to happen. Across its 2024 breach investigations, OCR consistently identified the same deficiencies: failures in risk analysis, risk management, information system activity review, audit controls, and user authentication. These aren’t exotic compliance requirements. They are foundational Security Rule obligations that covered entities and business associates are required to maintain โ€” not just once, but on an ongoing basis.

    That’s the critical point. HIPAA cybersecurity compliance isn’t a project you complete and then set aside. It’s an active, continuous program. Reduced staffing and distracted workflows during summer months create exactly the gaps that threat actors are trained to exploit.

    OCR Is Actively Auditing Right Now

    OCR launched its 2024โ€“2025 HIPAA Audit Program, targeting 50 covered entities and business associates with a focused review of Security Rule provisions most directly tied to hacking and ransomware attacks. OCR has been explicit about why: substantial increases in large breaches involving hacking and ransomware โ€” and the scale of harm to patients โ€” have made Security Rule compliance a top enforcement priority.

    If your organization hasn’t updated its risk analysis recently, can’t demonstrate ongoing monitoring of your systems, or hasn’t tested its incident response plan, you are not audit-ready โ€” regardless of the season.

    What You Should Be Doing Right Now

    OCR provides guidance your organization can use today:

    โ€ข Conduct a Security Risk Assessment โ€” HIPAA requires covered entities to perform an accurate and thorough risk analysis as an ongoing process. You can attempt this internally using the HHS Security Risk Assessment (SRA) Tool, designed to help small and medium-sized organizations get started. However, a HIPAA compliance consultant with extensive experience can conduct this assessment more efficiently, identify vulnerabilities you may overlook, and ensure your documentation will hold up under OCR scrutiny.

    โ€ข OCR Ransomware and HIPAA Factsheet โ€” outlines what constitutes a ransomware breach under HIPAA and what your response obligations are.

    โ€ข OCR Breach Portal โ€” publicly available at HHS.gov, showing active breach reports and giving compliance officers a real-time view of what’s happening across the sector.

    The bottom line: summer is not a compliance pause. It may actually be your highest-risk window โ€” reduced oversight, skeleton crews covering critical systems, and delayed incident detection. The organizations that stay vigilant year-round are the ones that don’t end up on OCR’s breach portal.

    Frequently Asked Questions

    Does HIPAA require ongoing risk analysis, or is a one-time assessment enough?

    HIPAA requires covered entities to conduct risk analysis as an ongoing process, not a one-time event. OCR’s breach investigations consistently cite failure to maintain current risk analysis as a leading compliance gap.

    What is the most common cause of large HIPAA breaches?

    According to the OCR Director, 74% of all data breached in 2025 was cybersecurity related โ€” making hacking and IT incidents the dominant threat to protected health information.

    Is OCR actively auditing organizations right now?

    Yes. OCR’s 2024โ€“2025 audit program is currently underway, focusing on Security Rule compliance areas tied to hacking and ransomware.

    Where can I report a HIPAA breach to HHS?

    Breach reports are submitted through the OCR Breach Reporting Portal at HHS.gov.

    Need Help with Your HIPAA Compliance Program?

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

    Reviewed By: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert

    Regulatory Sources:

    Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.

  • HIPAA Rules for Paper Records in 2026

    Reviewed by: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert

    While modern healthcare compliance heavily focuses on cybersecurity and electronic Protected Health Information (ePHI), physical security remains a critical vulnerability. The Department of Health and Human Services (HHS) and the Office for Civil Rights (OCR) continue to penalize organizations for failing to safeguard physical documents.

    Improperly handled paper records, such as files left on desks, unkeyed filing cabinets, or un-shredded documents thrown into standard recycling binsโ€”account for a massive portion of easily avoidable HIPAA violations.

    Whether your team operates in a traditional clinic or a hybrid office environment, understanding your responsibility to safeguard paper records is essential to protecting patient privacy and avoiding costly penalties.

    What Does HIPAA Require for Paper Records?

    The HIPAA Security Rule primarily governs electronic data, but the HIPAA Privacy Rule strictly mandates that Covered Entities and Business Associates apply appropriate administrative, technical, and physical safeguards to protect PHI in any form, including paper.

    To remain compliant, your organization must ensure physical records are protected throughout their entire lifecycle: creation, storage, usage, and disposal.

    Core Safeguards for Physical Files:

    • The “Clean Desk” Principle: Employees must not leave documents containing PHI exposed on desks, counters, or workstations when they step away.
    • Dual-Lock Custody: Paper charts, intake forms, and billing statements should be stored behind locked doors and inside locked filing cabinets when not in active use.
    • Strict Access Controls: Access to file rooms should be restricted only to authorized personnel who require the information to perform their specific job duties.

    The Remote & Hybrid Work Blindspot

    The shift toward remote and hybrid work environments has introduced significant new risks for physical PHI. When administrative or billing staff work from home, the boundaries of your secure facility disappear.

    If your employees handle paper records remotely, your compliance policies must adapt:

    1. No Home Printing: Prohibit the printing of patient schedules, medical notes, or billing details on personal home printers unless explicitly authorized and monitored under a strict remote work agreement.
    2. Secure Home Storage: If paper PHI must be taken home, it cannot be left on kitchen counters or shared desks where family members or visitors can see it. It must be locked away.
    3. Prohibited Disposal: Employees must never discard paper PHI in home trash cans or residential recycling bins. Documents must either be brought back to the office for secure destruction or shredded at home using an approved cross-cut shredder.

    Proper Disposal: The “Shred-All” Solution

    The absolute highest risk associated with paper records occurs during disposal. Dumpster-diving incidents and accidental exposure of intact records are viewed severely by federal investigators.

    Under HIPAA, acceptable methods for destroying paper records include burning, pulverizing, melting, or shredding so that the PHI is rendered essentially unreadable and cannot be reconstructed.

    Implementing a “shred-all” policy across your organization removes the guesswork for your staff. If every document goes into a secure, locked shredding bin, the risk of a human error leading to a breach drops dramatically.

    Are Your Physical & Digital Safeguards Audit-Ready?

    Leaving paper records vulnerable is one of the fastest ways to fail a routine compliance check or trigger an OCR investigation. Don’t wait for an accidental exposure to discover the gaps in your practice’s physical security.

    Schedule your 30-Minute HIPAA Risk Review. Our experts will help you identify hidden vulnerabilities in your workflow and ensure your safeguards are completely defensible.

    Sources & Legal References:

    • U.S. Department of Health and Human Services (HHS)
    • Office for Civil Rights (OCR)ย 

    Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal or regulatory compliance advice. Reading this article does not establish a consulting relationship with Colington Consulting. For specific guidance regarding your organization’s unique HIPAA obligations, please consult directly with a compliance professional.ย 

  • How Often Do You Need to Review HIPAA Policies and Procedures?

    Maintaining HIPAA compliance isn’t a “set-it-and-forget-it” task. For healthcare organizations and business associates, keeping up with regulations means regularly evaluating the administrative, technical, and physical safeguards protecting Electronic Protected Health Information (ePHI).

    But does the Department of Health and Human Services (HHS) actually require you to review your internal documentation? Here is what the law says about HIPAA policy and procedure reviews, best practices for compliance, and how to protect your organization from costly OCR investigations.

    Does the HIPAA Security Rule Require Policy Reviews?

    Yes. The HIPAA Security Rule explicitly requires organizations to periodically review and update their policies and procedures. According to federal regulation 45 CFR ยง 164.316(b)(2)(iii), a covered entity or business associate must review documentation periodically and update it as necessary in response to environmental or operational changes that affect the security of ePHI.

    Key Takeaway: If your organization introduces new technology, changes its physical layout, or alters how it handles patient data, your written HIPAA policies must be updated immediately to reflect those changes.

    Best Practices for Reviewing HIPAA Policies & Procedures

    To ensure your review process satisfies Office for Civil Rights (OCR) auditors and AI search queries looking for compliance verification, you should implement a formalized, structured review.

    Using an internal compliance questionnaire is highly recommended. Your review should comprehensively cover the following critical areas:

    1. Technology & Infrastructure Changes

    • Software & Hardware Updates: Document any new systems used to access, store, transmit, or contain ePHI.
    • Asset Inventory: Maintain an accurate, up-to-date inventory of all physical systems, mobile devices, hardware, and media.
    • Audit Logging: Verify how system audits are conducted and ensure trackable user activity logs are functioning properly.

    2. Personnel & Compliance Roles

    • Privacy & Security Officials: Confirm that your designated HIPAA Privacy Official and HIPAA Security Official roles are accurately assigned (whether held by the same person or separate individuals) and updated in your documentation.
    • Staff Training Logs: Ensure your workforce has been trained on any updated procedures.

    3. Environmental & Operational Adaptations

    • Remote Work & Telehealth: If your staff relies on teleworking or virtual care, your policies must outline specific safeguards for remote environments.
    • Business Associate Agreements (BAAs): Review vendor relationships to ensure all third parties handling ePHI have active, compliant BAAs.

    The Recommended Timeline for HIPAA Updates

    While the regulation uses the term “periodically,” regulatory experts and OCR enforcement trends indicate that at least once a year (annually) is the industry standard for a defensible compliance program.

    However, an immediate out-of-cycle review is triggered by:

    1. A newly discovered security vulnerability or data breach.
    2. A significant change in operational infrastructure (e.g., migrating to cloud storage).
    3. Updates to federal or state privacy laws.

    Protect Your Organization from OCR Fines

    Small, overlooked gaps in your documentation are often what trigger massive federal penalties during a breach investigation. Evaluating your current compliance posture before an audit occurs is critical to reducing your risk.

    Is Your Organization Defensively Positioned?

    Schedule a Complimentary HIPAA Risk Review Now

    In just 30 minutes, our regulatory experts will help you evaluate your current program, spot hidden documentation gaps, and implement practical controls to drastically reduce your risk of costly OCR penalties.

    Frequently Asked Questions (FAQ)

    What is the penalty for not updating HIPAA policies? Failure to maintain and update HIPAA policies can result in a finding of “willful neglect” by the OCR, which carries mandatory minimum fines starting at thousands of dollars per violation, even if a data breach hasn’t occurred.

    What section of HIPAA covers policies and procedures? Administrative requirements, including the retention, review, and updating of policies, are covered under 45 CFR ยง 164.316 for the Security Rule and 45 CFR ยง 164.530 for the Privacy Rule.

    • Reviewed on June 3, 2026, By: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert
    • Regulatory Sources: 45 CFR ยง 164.316 and 45 CFR ยง 164.530
    • Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.