
2026 HIPAA Security Rule: The SRA Audit Risk for Independent Medical Practices
What included in this intelligence brief
Why OCR is intensifying scrutiny of HIPAA Security Risk Analyses and why independent practices can face enforcement even without a major breach or ransomware attack.
What an OCR-ready risk analysis must demonstrate, including where ePHI resides, how it moves, what can compromise it, and whether identified risks were actually addressed.
Downloadable Phase 1 Governance Pack for an Independent Medical Practice with checklists
How to prepare for scrutiny with a practical 30–60–90 day framework covering governance, ePHI inventory, technical controls, remediation, testing, and the evidence OCR may request.
The U.S. Department of Health and Human Services Office for Civil Rights (OCR) is placing increasing enforcement emphasis on the HIPAA Security Rule's risk-analysis requirement.
This matters particularly for independent practices. A practice does not need to experience a ransomware attack, report a large breach, or operate a hospital-sized IT environment to face scrutiny. OCR has repeatedly pursued smaller providers when investigations found a failure to conduct an accurate, thorough assessment of risks to electronic protected health information (ePHI).
Recent enforcement demonstrates the point. In April 2026, OCR announced four ransomware settlements and said the actions brought its completed investigations under its Risk Analysis Initiative to 13. The settlements involved payments ranging from $225,000 to $375,000.
In February 2026, OCR settled with Top of the World Ranch Treatment Center after finding that the provider had failed to conduct an accurate and thorough risk analysis. The provider paid $103,000 and accepted a two-year corrective action plan.
A separate 2025 settlement involving Comprehensive Neurology, a small New York neurology practice, resulted in a $25,000 payment following a ransomware investigation in which OCR identified the absence of an adequate risk analysis.
Practices should therefore be able to produce, on demand:
a current and documented Security Risk Analysis;
a corresponding risk-management plan;
an inventory of systems and devices handling ePHI;
evidence of access controls and authentication;
evidence that ePHI is protected in transit and at rest where appropriate;
audit-log and monitoring procedures;
backup and recovery controls;
workforce security and training records;
incident-response procedures; and
evidence that identified risks were actually addressed.
1. The Regulatory Position in 2026
There is an important distinction between current law and the direction of OCR's proposed reforms.
The HIPAA Security Rule currently requires covered entities to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI. It also requires reasonable and appropriate security measures to reduce identified risks to an appropriate level.
The current rule retains the distinction between required and addressable implementation specifications.
“Addressable” does not mean optional. Where an addressable specification is reasonable and appropriate, the practice must implement it. If it determines that an alternative measure is appropriate, it must document that decision and implement an alternative that achieves the purpose of the standard.
What is changing or may change
OCR's December 2024 proposed Security Rule amendments would substantially increase the technical baseline.
Among other proposals, OCR would:
eliminate the required/addressable distinction;
require encryption of ePHI at rest and in transit, subject to limited exceptions;
require multi-factor authentication, subject to limited exceptions;
require annual compliance audits;
require technology-asset inventories and network maps;
impose more specific risk-analysis documentation requirements;
require vulnerability scanning at least every six months;
require penetration testing at least annually; and
establish additional requirements for incident response, backup and recovery.
Those provisions are proposed, not the current Security Rule. HHS's current Security Rule summary, updated August 7, 2026, continues to describe the existing addressable framework.
For practice administrators, however, this creates an important planning issue: MFA and encryption should be treated as priority security controls even where a particular implementation specification remains addressable under the current rule. OCR's recent guidance repeatedly points practices toward stronger authentication, encryption, audit controls and system hardening.
2. Why the Security Risk Analysis Has Become the Critical Document
OCR describes risk analysis as the foundation of Security Rule compliance.
A defensible SRA should establish:
1. What ePHI the practice holds
Examples:
EHR records
patient portals
diagnostic images
laboratory results
billing records
email
cloud storage
backups
mobile devices
removable media
third-party applications
2. Where the ePHI resides
The practice should identify systems, applications, devices, and vendors that create, receive, maintain, or transmit ePHI.
3. How ePHI moves
Map the major pathways:

The objective is to identify points at which ePHI can be accessed, altered, lost, intercepted, or unavailable.
4. What can go wrong
Examples include:
phishing;
stolen credentials;
ransomware;
lost laptops;
unsupported software;
excessive user privileges;
unauthorized remote access;
unencrypted devices;
exposed cloud storage;
inadequate backups;
vendor compromise;
terminated employees retaining access.
5. What the practice is doing about each risk
The SRA should connect each material risk to a mitigation measure, responsible person, and status.
OCR's guidance specifically states that risk-analysis documentation should identify risk levels and corrective actions. It also emphasizes that risk analysis is an ongoing process rather than a one-time exercise.
3. What an OCR Review Can Look Like
OCR's audit protocol examines administrative, physical and technical safeguards and requires selected entities to produce specific documentation.
The audit protocol states that entities should provide the requested documents rather than broad compilations of every policy they maintain. Documents generally reflect the versions in use when the audit notification and document request are issued.
A practice receiving an OCR inquiry should therefore avoid creating documents retrospectively and presenting them as historical evidence.
The practical audit sequence
Stage | What the practice should expect |
|---|---|
1. OCR contact | Verification of the request and scope |
2. Document request | OCR identifies specific policies, records or evidence required |
3. Internal evidence collection | Compliance, management and IT assemble responsive documentation |
4. Technical validation | Practice verifies that written policies match actual system configurations |
5. OCR review | OCR evaluates documented compliance and implementation |
6. Follow-up | OCR may request clarification, additional evidence or corrective action |
7. Resolution | Informal resolution, resolution agreement/CAP, or potentially civil money penalties |
OCR's current audit program states that its audits are intended not only to identify compliance problems but also to discover risks and vulnerabilities before they result in breaches.
4. The Independent Practice Audit Protocol
A small practice should be able to complete the following exercise internally.
Phase 1 — Governance
Confirm:
Security official assigned
HIPAA compliance responsibility documented
Current HIPAA policies approved
Business associate agreements maintained
Security responsibilities assigned to vendors/IT providers
Workforce training records available
Incident-response responsibility assigned
Download Sample Phase 1 Governance Pack for an Independent Medical Practice
Phase 2 — ePHI Inventory
Create a simple inventory of every system touching ePHI.
Asset | ePHI? | Owner | Location | Vendor | Encryption | MFA | Backup |
|---|---|---|---|---|---|---|---|
EHR | Yes | Practice | Cloud | Vendor | Verify | Verify | Verify |
Yes | Practice | Cloud | Vendor | Verify | Verify | Verify | |
Laptops | Potentially | IT | Practice/home | IT provider | Verify | N/A | N/A |
Imaging | Yes | Clinical | Cloud/on-prem | Vendor | Verify | Verify | Verify |
Billing | Yes | Billing | Cloud | Vendor | Verify | Verify | Verify |
The inventory should include systems that administrators may overlook — such as scanners, tablets, phones, remote-access tools, backup platforms, and cloud applications.
5. SRA Risk Scoring
A simple risk matrix is sufficient if it is consistently applied.
Likelihood
1 — Low: Unlikely to occur
2 — Moderate: Plausible
3 — High: Credible and reasonably foreseeable
Impact
1 — Low: Limited effect
2 — Moderate: Material operational/privacy impact
3 — High: Significant patient, operational or regulatory impact
Risk Score
Likelihood × Impact
Score | Priority |
|---|---|
1–2 | Monitor |
3–4 | Remediate |
6–9 | Immediate action |
The methodology itself is less important than showing that the practice has systematically identified risks, evaluated them and acted on them. OCR does not prescribe a single SRA format.
6. Technical Remediation Checklist
Identity & Access
Unique user accounts
No shared administrative credentials
Role-based access
Former employees disabled promptly
Vendor accounts reviewed
Privileged accounts restricted
Password policies enforced
MFA enabled where technically available and appropriate
Remote access protected by strong authentication
Priority: Critical
Encryption
Laptop encryption enabled
Mobile-device encryption enabled
Server/storage encryption evaluated
Cloud-provider encryption verified
Email transmission safeguards evaluated
Portable media encrypted or prohibited
Encryption decisions documented in the SRA
Priority: Critical
The current rule requires transmission security and contains addressable encryption specifications; OCR guidance nevertheless recommends encryption of ePHI at rest and in transit where appropriate. The proposed Security Rule would make encryption substantially more prescriptive.
Endpoint Security
Supported operating systems
Automatic security updates
Antivirus/anti-malware
Endpoint detection/response where appropriate
Firewall enabled
Unnecessary software removed
Unused ports/services disabled where appropriate
USB/removable media controlled
Lost-device procedure established
OCR's January 2026 cybersecurity guidance specifically highlighted patching, vulnerability identification, system hardening and secure configuration.
Network Security
Secure Wi-Fi configuration
Separate guest Wi-Fi
Firewall maintained
Remote access secured
Network devices patched
Administrative interfaces restricted
Network segmentation evaluated
Internet-facing systems identified
Vulnerability scanning performed where appropriate
Backup & Recovery
Critical ePHI backed up
Backups protected from ransomware
At least one backup isolated from production systems
Backup restoration tested
Recovery responsibilities documented
Recovery priorities documented
Backup vendor covered by appropriate contractual arrangements
Do not accept “we have backups” as evidence of resilience.
The practice should be able to demonstrate that it can actually restore critical systems and records.
Logging & Monitoring
EHR access logging enabled
Administrative activity logged
Failed authentication monitored
Security alerts reviewed
Audit logs retained appropriately
Review responsibility assigned
Suspicious activity escalation process documented
OCR has repeatedly identified audit controls and regular review of information-system activity as important security measures in recent enforcement actions.
7. The 30–60–90 Day Remediation Plan
First 30 Days — Establish Control
Management
Assign security responsibility.
Locate the most recent SRA.
Determine whether it is complete and current.
Build the ePHI/system inventory.
Identify critical vendors and business associates.
IT
Enable MFA on priority systems.
Confirm endpoint encryption.
Patch unsupported or vulnerable systems.
Disable former-user accounts.
Verify backups.
Compliance
Establish the SRA evidence folder.
Collect policies and training records.
Review BAAs.
Create a risk register.
Days 31–60 — Close Material Gaps
Complete remediation of:
privileged access;
remote access;
encryption gaps;
unsupported software;
backup weaknesses;
excessive permissions;
logging deficiencies;
vendor-access issues.
Every identified deficiency should have:
Owner → Action → Deadline → Evidence of completion
Days 61–90 — Test the Practice
Run an internal mock OCR review.
Ask:
“If OCR requested this document today, could we produce it?”
Then test the technical environment.
Do not simply review the policy.
For example:
Policy says: MFA is required.
Test: Select five accounts and verify MFA is actually enabled.
Policy says: terminated users are removed.
Test: Select five recent departures and verify account termination dates.
Policy says: backups are tested.
Test: Produce the most recent restoration-test evidence.
The objective is documented implementation, not documentation alone.
8. Penalty Exposure
HIPAA civil money penalties are determined by the nature of the violation, culpability, duration, harm, compliance history and other factors.
For 2026, the inflation-adjusted statutory figures include:
Culpability | 2026 minimum | 2026 maximum |
|---|---|---|
No knowledge | $145 | $73,011 |
Reasonable cause | $1,461 | $73,011 |
Willful neglect — corrected | $14,602 | $73,011 |
Willful neglect — not corrected | $73,011 | $2,190,294 |
The inflation-adjusted calendar-year cap is $2,190,294 for the statutory HIPAA penalty framework. OCR's separate 2019 enforcement-discretion policy affects the amounts it applies in many circumstances, so practices should not assume that the statutory maximum is automatically the amount OCR will impose.
More importantly, recent settlements demonstrate the practical exposure.
Recent enforcement signals
Comprehensive Neurology — $25,000
A small neurology practice affected by ransomware. OCR identified failure to conduct an accurate and thorough risk analysis.
Top of the World Ranch Treatment Center — $103,000
OCR's investigation followed a phishing incident affecting approximately 1,980 individuals. The settlement included a two-year corrective action plan.
Regional Women's Health Group — $320,000
OCR found, among other issues, failure to conduct an accurate and thorough risk analysis following a ransomware incident.
Assured Imaging — $375,000
OCR identified risk-analysis failures and other HIPAA violations following a ransomware incident affecting approximately 244,813 individuals.
These cases should not be read as a pricing schedule for HIPAA violations. Settlement amounts depend heavily on the facts, affected population, duration, cooperation, remediation and other enforcement factors.
9. What OCR Is Likely to Care About Most
A practice preparing for scrutiny should prioritize five questions.
1. Can you prove you performed the SRA?
Not:
“Our IT company handles HIPAA.”
But:
“Here is our documented assessment, dated X, covering these systems, risks and vulnerabilities.”
2. Did the SRA actually cover the environment?
If the practice uses:
cloud EHR;
Microsoft 365 or Google Workspace;
telehealth;
imaging systems;
patient portals;
mobile devices;
remote workers;
third-party billing;
those systems should appear in the risk assessment where they create, receive, maintain or transmit ePHI.
3. Did you act on identified risks?
An SRA that identifies a critical vulnerability but contains no remediation plan creates a second problem.
4. Can you prove controls exist?
OCR's recent enforcement actions repeatedly emphasize actual implementation — authentication, audit controls, encryption, risk management and workforce training.
5. Are your documents consistent with reality?
A policy saying “MFA is mandatory” does not establish that MFA is enabled.
A backup policy does not prove a successful restoration.
A training policy does not prove employees were trained.
The strongest compliance file connects:
Requirement → Policy → Technical control → Test → Evidence
10. The Practice's “OCR-Ready” Evidence Folder
Every independent practice should maintain a controlled evidence repository containing:
A. Governance
Security official designation
HIPAA policies
Security procedures
Workforce training records
Incident-response plan
B. Risk Management
Current SRA
Previous SRA
Risk register
Remediation plan
Remediation evidence
C. Technology
Asset inventory
Software inventory
Network diagram
EHR documentation
Encryption configuration
MFA configuration
Backup configuration
D. Access
User-access reviews
Privileged-account list
Termination records
Vendor-access records
Remote-access configuration
E. Monitoring
Audit logs
Security alerts
Log-review records
Vulnerability reports
Penetration-test reports, where performed
F. Vendors
Business associate agreements
Vendor security documentation
Cloud-provider documentation
Incident-notification provisions
G. Incidents
Incident log
Breach assessments
Investigation records
Corrective actions
Lessons learned
Retention matters. HIPAA requires Security Rule documentation to be retained for six years from its creation or the date it was last in effect, whichever is later.
11. The 10 Questions Every Practice Should Answer Today
When was our last complete SRA?
Does it cover every system containing ePHI?
Who is responsible for updating it?
Can we produce our current ePHI inventory?
Is MFA enabled on our highest-risk systems?
Are laptops and mobile devices encrypted?
Can we demonstrate that backups can actually be restored?
Can we produce evidence of access reviews and terminated-user removal?
Which material risks remain unresolved?
Can we prove what we say our security policies require?
If the answer to questions 1, 2 or 9 is unclear, the practice should treat the matter as a compliance priority.
Bottom Line
The most important development for independent practices is not that OCR has suddenly created a universal MFA or encryption mandate. It has not. Those requirements remain part of OCR's proposed modernization of the Security Rule as of September 2026.
The more immediate issue is the enforcement trajectory already visible in OCR's actions.
OCR is using cybersecurity incidents to examine whether regulated entities understood their risks before the incident occurred — and whether they had taken reasonable measures to reduce those risks.
For an independent practice, the practical standard is therefore simple:
Know where your ePHI is.
Know how it moves.
Know what can compromise it.
Document the risks.
Fix the important gaps.
Test the controls.
Keep the evidence.
An SRA that exists only because an OCR letter arrived is already late.
Regulatory Reference Points
Current rule: 45 C.F.R. §§ 164.302–318 — HIPAA Security Rule.
Risk analysis: 45 C.F.R. § 164.308(a)(1)(ii)(A).
Risk management: 45 C.F.R. § 164.308(a)(1)(ii)(B).
Technical safeguards: 45 C.F.R. § 164.312.
Documentation: 45 C.F.R. § 164.316.
OCR audit authority: HITECH Act § 13411.
Proposed Security Rule modernization: HHS/OCR Notice of Proposed Rulemaking, December 27, 2024.
2026 enforcement position: OCR risk-analysis and ransomware enforcement actions announced through September 2026.
Editorial Note
This intelligence brief reflects the HIPAA Security Rule and OCR enforcement information available as of September 28, 2026. The distinction between current requirements and proposed Security Rule amendments is intentional. Practices should evaluate applicable state privacy/security laws, contractual requirements, and other federal requirements separately. This publication is regulatory intelligence, not legal advice.
Finish Reading the Full Story and Expert Analysis.
Get the latest legal & regulatory intelligence in United States
Wansom is AI and can make mistakes.
