2026 HIPAA Security Rule: The SRA Audit Risk for Independent Medical Practices
circular
Premium

2026 HIPAA Security Rule: The SRA Audit Risk for Independent Medical Practices

United States··Briefly Editorial⏱️ 13 min read

What included in this intelligence brief

  • Why OCR is intensifying scrutiny of HIPAA Security Risk Analyses and why independent practices can face enforcement even without a major breach or ransomware attack.

  • What an OCR-ready risk analysis must demonstrate, including where ePHI resides, how it moves, what can compromise it, and whether identified risks were actually addressed.

  • Downloadable Phase 1 Governance Pack for an Independent Medical Practice  with checklists

  • How to prepare for scrutiny with a practical 30–60–90 day framework covering governance, ePHI inventory, technical controls, remediation, testing, and the evidence OCR may request.

The U.S. Department of Health and Human Services Office for Civil Rights (OCR) is placing increasing enforcement emphasis on the HIPAA Security Rule's risk-analysis requirement.

This matters particularly for independent practices. A practice does not need to experience a ransomware attack, report a large breach, or operate a hospital-sized IT environment to face scrutiny. OCR has repeatedly pursued smaller providers when investigations found a failure to conduct an accurate, thorough assessment of risks to electronic protected health information (ePHI).

Recent enforcement demonstrates the point. In April 2026, OCR announced four ransomware settlements and said the actions brought its completed investigations under its Risk Analysis Initiative to 13. The settlements involved payments ranging from $225,000 to $375,000.

In February 2026, OCR settled with Top of the World Ranch Treatment Center after finding that the provider had failed to conduct an accurate and thorough risk analysis. The provider paid $103,000 and accepted a two-year corrective action plan.

A separate 2025 settlement involving Comprehensive Neurology, a small New York neurology practice, resulted in a $25,000 payment following a ransomware investigation in which OCR identified the absence of an adequate risk analysis.

Practices should therefore be able to produce, on demand:

  • a current and documented Security Risk Analysis;

  • a corresponding risk-management plan;

  • an inventory of systems and devices handling ePHI;

  • evidence of access controls and authentication;

  • evidence that ePHI is protected in transit and at rest where appropriate;

  • audit-log and monitoring procedures;

  • backup and recovery controls;

  • workforce security and training records;

  • incident-response procedures; and

  • evidence that identified risks were actually addressed.


1. The Regulatory Position in 2026

There is an important distinction between current law and the direction of OCR's proposed reforms.

The HIPAA Security Rule currently requires covered entities to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI. It also requires reasonable and appropriate security measures to reduce identified risks to an appropriate level.

The current rule retains the distinction between required and addressable implementation specifications.

“Addressable” does not mean optional. Where an addressable specification is reasonable and appropriate, the practice must implement it. If it determines that an alternative measure is appropriate, it must document that decision and implement an alternative that achieves the purpose of the standard.

What is changing or may change

OCR's December 2024 proposed Security Rule amendments would substantially increase the technical baseline.

Among other proposals, OCR would:

  • eliminate the required/addressable distinction;

  • require encryption of ePHI at rest and in transit, subject to limited exceptions;

  • require multi-factor authentication, subject to limited exceptions;

  • require annual compliance audits;

  • require technology-asset inventories and network maps;

  • impose more specific risk-analysis documentation requirements;

  • require vulnerability scanning at least every six months;

  • require penetration testing at least annually; and

  • establish additional requirements for incident response, backup and recovery.

Those provisions are proposed, not the current Security Rule. HHS's current Security Rule summary, updated August 7, 2026, continues to describe the existing addressable framework.

For practice administrators, however, this creates an important planning issue: MFA and encryption should be treated as priority security controls even where a particular implementation specification remains addressable under the current rule. OCR's recent guidance repeatedly points practices toward stronger authentication, encryption, audit controls and system hardening.


2. Why the Security Risk Analysis Has Become the Critical Document

OCR describes risk analysis as the foundation of Security Rule compliance.

A defensible SRA should establish:

1. What ePHI the practice holds

Examples:

  • EHR records

  • patient portals

  • diagnostic images

  • laboratory results

  • billing records

  • email

  • cloud storage

  • backups

  • mobile devices

  • removable media

  • third-party applications

2. Where the ePHI resides

The practice should identify systems, applications, devices, and vendors that create, receive, maintain, or transmit ePHI.

3. How ePHI moves

Map the major pathways:

Gemini_Generated_Image_7qgfxm7qgfxm7qgf

The objective is to identify points at which ePHI can be accessed, altered, lost, intercepted, or unavailable.

4. What can go wrong

Examples include:

  • phishing;

  • stolen credentials;

  • ransomware;

  • lost laptops;

  • unsupported software;

  • excessive user privileges;

  • unauthorized remote access;

  • unencrypted devices;

  • exposed cloud storage;

  • inadequate backups;

  • vendor compromise;

  • terminated employees retaining access.

5. What the practice is doing about each risk

The SRA should connect each material risk to a mitigation measure, responsible person, and status.

OCR's guidance specifically states that risk-analysis documentation should identify risk levels and corrective actions. It also emphasizes that risk analysis is an ongoing process rather than a one-time exercise.


3. What an OCR Review Can Look Like

OCR's audit protocol examines administrative, physical and technical safeguards and requires selected entities to produce specific documentation.

The audit protocol states that entities should provide the requested documents rather than broad compilations of every policy they maintain. Documents generally reflect the versions in use when the audit notification and document request are issued.

A practice receiving an OCR inquiry should therefore avoid creating documents retrospectively and presenting them as historical evidence.

The practical audit sequence

Stage

What the practice should expect

1. OCR contact

Verification of the request and scope

2. Document request

OCR identifies specific policies, records or evidence required

3. Internal evidence collection

Compliance, management and IT assemble responsive documentation

4. Technical validation

Practice verifies that written policies match actual system configurations

5. OCR review

OCR evaluates documented compliance and implementation

6. Follow-up

OCR may request clarification, additional evidence or corrective action

7. Resolution

Informal resolution, resolution agreement/CAP, or potentially civil money penalties

OCR's current audit program states that its audits are intended not only to identify compliance problems but also to discover risks and vulnerabilities before they result in breaches.


4. The Independent Practice Audit Protocol

A small practice should be able to complete the following exercise internally.

Phase 1 — Governance

Confirm:

  • Security official assigned

  • HIPAA compliance responsibility documented

  • Current HIPAA policies approved

  • Business associate agreements maintained

  • Security responsibilities assigned to vendors/IT providers

  • Workforce training records available

  • Incident-response responsibility assigned

Download Sample Phase 1 Governance Pack for an Independent Medical Practice


Phase 2 — ePHI Inventory

Create a simple inventory of every system touching ePHI.

Asset

ePHI?

Owner

Location

Vendor

Encryption

MFA

Backup

EHR

Yes

Practice

Cloud

Vendor

Verify

Verify

Verify

Email

Yes

Practice

Cloud

Vendor

Verify

Verify

Verify

Laptops

Potentially

IT

Practice/home

IT provider

Verify

N/A

N/A

Imaging

Yes

Clinical

Cloud/on-prem

Vendor

Verify

Verify

Verify

Billing

Yes

Billing

Cloud

Vendor

Verify

Verify

Verify

The inventory should include systems that administrators may overlook — such as scanners, tablets, phones, remote-access tools, backup platforms, and cloud applications.


5. SRA Risk Scoring

A simple risk matrix is sufficient if it is consistently applied.

Likelihood

1 — Low: Unlikely to occur
2 — Moderate: Plausible
3 — High: Credible and reasonably foreseeable

Impact

1 — Low: Limited effect
2 — Moderate: Material operational/privacy impact
3 — High: Significant patient, operational or regulatory impact

Risk Score

Likelihood × Impact

Score

Priority

1–2

Monitor

3–4

Remediate

6–9

Immediate action

The methodology itself is less important than showing that the practice has systematically identified risks, evaluated them and acted on them. OCR does not prescribe a single SRA format.


6. Technical Remediation Checklist

Identity & Access

  • Unique user accounts

  • No shared administrative credentials

  • Role-based access

  • Former employees disabled promptly

  • Vendor accounts reviewed

  • Privileged accounts restricted

  • Password policies enforced

  • MFA enabled where technically available and appropriate

  • Remote access protected by strong authentication

Priority: Critical


Encryption

  • Laptop encryption enabled

  • Mobile-device encryption enabled

  • Server/storage encryption evaluated

  • Cloud-provider encryption verified

  • Email transmission safeguards evaluated

  • Portable media encrypted or prohibited

  • Encryption decisions documented in the SRA

Priority: Critical

The current rule requires transmission security and contains addressable encryption specifications; OCR guidance nevertheless recommends encryption of ePHI at rest and in transit where appropriate. The proposed Security Rule would make encryption substantially more prescriptive.


Endpoint Security

  • Supported operating systems

  • Automatic security updates

  • Antivirus/anti-malware

  • Endpoint detection/response where appropriate

  • Firewall enabled

  • Unnecessary software removed

  • Unused ports/services disabled where appropriate

  • USB/removable media controlled

  • Lost-device procedure established

OCR's January 2026 cybersecurity guidance specifically highlighted patching, vulnerability identification, system hardening and secure configuration.


Network Security

  • Secure Wi-Fi configuration

  • Separate guest Wi-Fi

  • Firewall maintained

  • Remote access secured

  • Network devices patched

  • Administrative interfaces restricted

  • Network segmentation evaluated

  • Internet-facing systems identified

  • Vulnerability scanning performed where appropriate


Backup & Recovery

  • Critical ePHI backed up

  • Backups protected from ransomware

  • At least one backup isolated from production systems

  • Backup restoration tested

  • Recovery responsibilities documented

  • Recovery priorities documented

  • Backup vendor covered by appropriate contractual arrangements

Do not accept “we have backups” as evidence of resilience.

The practice should be able to demonstrate that it can actually restore critical systems and records.


Logging & Monitoring

  • EHR access logging enabled

  • Administrative activity logged

  • Failed authentication monitored

  • Security alerts reviewed

  • Audit logs retained appropriately

  • Review responsibility assigned

  • Suspicious activity escalation process documented

OCR has repeatedly identified audit controls and regular review of information-system activity as important security measures in recent enforcement actions.


7. The 30–60–90 Day Remediation Plan

First 30 Days — Establish Control

Management

  • Assign security responsibility.

  • Locate the most recent SRA.

  • Determine whether it is complete and current.

  • Build the ePHI/system inventory.

  • Identify critical vendors and business associates.

IT

  • Enable MFA on priority systems.

  • Confirm endpoint encryption.

  • Patch unsupported or vulnerable systems.

  • Disable former-user accounts.

  • Verify backups.

Compliance

  • Establish the SRA evidence folder.

  • Collect policies and training records.

  • Review BAAs.

  • Create a risk register.


Days 31–60 — Close Material Gaps

Complete remediation of:

  • privileged access;

  • remote access;

  • encryption gaps;

  • unsupported software;

  • backup weaknesses;

  • excessive permissions;

  • logging deficiencies;

  • vendor-access issues.

Every identified deficiency should have:

Owner → Action → Deadline → Evidence of completion


Days 61–90 — Test the Practice

Run an internal mock OCR review.

Ask:

“If OCR requested this document today, could we produce it?”

Then test the technical environment.

Do not simply review the policy.

For example:

Policy says: MFA is required.

Test: Select five accounts and verify MFA is actually enabled.

Policy says: terminated users are removed.

Test: Select five recent departures and verify account termination dates.

Policy says: backups are tested.

Test: Produce the most recent restoration-test evidence.

The objective is documented implementation, not documentation alone.


8. Penalty Exposure

HIPAA civil money penalties are determined by the nature of the violation, culpability, duration, harm, compliance history and other factors.

For 2026, the inflation-adjusted statutory figures include:

Culpability

2026 minimum

2026 maximum

No knowledge

$145

$73,011

Reasonable cause

$1,461

$73,011

Willful neglect — corrected

$14,602

$73,011

Willful neglect — not corrected

$73,011

$2,190,294

The inflation-adjusted calendar-year cap is $2,190,294 for the statutory HIPAA penalty framework. OCR's separate 2019 enforcement-discretion policy affects the amounts it applies in many circumstances, so practices should not assume that the statutory maximum is automatically the amount OCR will impose.

More importantly, recent settlements demonstrate the practical exposure.

Recent enforcement signals

Comprehensive Neurology — $25,000

A small neurology practice affected by ransomware. OCR identified failure to conduct an accurate and thorough risk analysis.

Top of the World Ranch Treatment Center — $103,000

OCR's investigation followed a phishing incident affecting approximately 1,980 individuals. The settlement included a two-year corrective action plan.

Regional Women's Health Group — $320,000

OCR found, among other issues, failure to conduct an accurate and thorough risk analysis following a ransomware incident.

Assured Imaging — $375,000

OCR identified risk-analysis failures and other HIPAA violations following a ransomware incident affecting approximately 244,813 individuals.

These cases should not be read as a pricing schedule for HIPAA violations. Settlement amounts depend heavily on the facts, affected population, duration, cooperation, remediation and other enforcement factors.


9. What OCR Is Likely to Care About Most

A practice preparing for scrutiny should prioritize five questions.

1. Can you prove you performed the SRA?

Not:

“Our IT company handles HIPAA.”

But:

“Here is our documented assessment, dated X, covering these systems, risks and vulnerabilities.”

2. Did the SRA actually cover the environment?

If the practice uses:

  • cloud EHR;

  • Microsoft 365 or Google Workspace;

  • telehealth;

  • imaging systems;

  • patient portals;

  • mobile devices;

  • remote workers;

  • third-party billing;

those systems should appear in the risk assessment where they create, receive, maintain or transmit ePHI.

3. Did you act on identified risks?

An SRA that identifies a critical vulnerability but contains no remediation plan creates a second problem.

4. Can you prove controls exist?

OCR's recent enforcement actions repeatedly emphasize actual implementation — authentication, audit controls, encryption, risk management and workforce training.

5. Are your documents consistent with reality?

A policy saying “MFA is mandatory” does not establish that MFA is enabled.

A backup policy does not prove a successful restoration.

A training policy does not prove employees were trained.

The strongest compliance file connects:

Requirement → Policy → Technical control → Test → Evidence


10. The Practice's “OCR-Ready” Evidence Folder

Every independent practice should maintain a controlled evidence repository containing:

A. Governance

  • Security official designation

  • HIPAA policies

  • Security procedures

  • Workforce training records

  • Incident-response plan

B. Risk Management

  • Current SRA

  • Previous SRA

  • Risk register

  • Remediation plan

  • Remediation evidence

C. Technology

  • Asset inventory

  • Software inventory

  • Network diagram

  • EHR documentation

  • Encryption configuration

  • MFA configuration

  • Backup configuration

D. Access

  • User-access reviews

  • Privileged-account list

  • Termination records

  • Vendor-access records

  • Remote-access configuration

E. Monitoring

  • Audit logs

  • Security alerts

  • Log-review records

  • Vulnerability reports

  • Penetration-test reports, where performed

F. Vendors

  • Business associate agreements

  • Vendor security documentation

  • Cloud-provider documentation

  • Incident-notification provisions

G. Incidents

  • Incident log

  • Breach assessments

  • Investigation records

  • Corrective actions

  • Lessons learned

Retention matters. HIPAA requires Security Rule documentation to be retained for six years from its creation or the date it was last in effect, whichever is later.


11. The 10 Questions Every Practice Should Answer Today

  1. When was our last complete SRA?

  2. Does it cover every system containing ePHI?

  3. Who is responsible for updating it?

  4. Can we produce our current ePHI inventory?

  5. Is MFA enabled on our highest-risk systems?

  6. Are laptops and mobile devices encrypted?

  7. Can we demonstrate that backups can actually be restored?

  8. Can we produce evidence of access reviews and terminated-user removal?

  9. Which material risks remain unresolved?

  10. Can we prove what we say our security policies require?

If the answer to questions 1, 2 or 9 is unclear, the practice should treat the matter as a compliance priority.


Bottom Line

The most important development for independent practices is not that OCR has suddenly created a universal MFA or encryption mandate. It has not. Those requirements remain part of OCR's proposed modernization of the Security Rule as of September 2026.

The more immediate issue is the enforcement trajectory already visible in OCR's actions.

OCR is using cybersecurity incidents to examine whether regulated entities understood their risks before the incident occurred — and whether they had taken reasonable measures to reduce those risks.

For an independent practice, the practical standard is therefore simple:

Know where your ePHI is.
Know how it moves.
Know what can compromise it.
Document the risks.
Fix the important gaps.
Test the controls.
Keep the evidence.

An SRA that exists only because an OCR letter arrived is already late.


Regulatory Reference Points

Current rule: 45 C.F.R. §§ 164.302–318 — HIPAA Security Rule.

Risk analysis: 45 C.F.R. § 164.308(a)(1)(ii)(A).

Risk management: 45 C.F.R. § 164.308(a)(1)(ii)(B).

Technical safeguards: 45 C.F.R. § 164.312.

Documentation: 45 C.F.R. § 164.316.

OCR audit authority: HITECH Act § 13411.

Proposed Security Rule modernization: HHS/OCR Notice of Proposed Rulemaking, December 27, 2024.

2026 enforcement position: OCR risk-analysis and ransomware enforcement actions announced through September 2026.

Editorial Note

This intelligence brief reflects the HIPAA Security Rule and OCR enforcement information available as of September 28, 2026. The distinction between current requirements and proposed Security Rule amendments is intentional. Practices should evaluate applicable state privacy/security laws, contractual requirements, and other federal requirements separately. This publication is regulatory intelligence, not legal advice.

Premium Content

Finish Reading the Full Story and Expert Analysis.

Get the latest legal & regulatory intelligence in United States

Instant access to full analysis, cited statutes & expert commentary
Customize your dashboard to track what matters to your business operations

Already have an account? Log in

Wansom is AI and can make mistakes.

2026 HIPAA Security Rule: The SRA Audit Risk for Independent Medical Practices | Briefly