By Chris Bowen | Founder & CEO, Bowen & Company
If you think the healthcare cybersecurity crisis is improving, the data tells a different story.
2025 became the worst year on record for large healthcare data breaches. The Office for Civil Rights (OCR) received 772 reports involving 500 or more individuals, exposing nearly 140 million patient records—surpassing the prior record set just two years earlier. (hipaajournal.com)
Read that again.
We're not plateauing. We're still trending in the wrong direction.
The headlines may change from week to week, but the bigger story isn't another ransomware attack or another healthcare organization making the news. The real story is that healthcare remains the most breached regulated industry in America.
And regulators are paying attention.
OCR Is Looking Beyond the Risk Assessment
For years, many organizations have focused on checking the compliance box:
"Yes, we completed our annual HIPAA Security Risk Assessment." (techtarget.com)
Increasingly, that's no longer enough.
OCR has made it clear through its ongoing enforcement actions that its focus is expanding beyond whether a risk analysis was performed. It is now increasingly focused on what organizations did with the results. Recent enforcement actions tied to ransomware investigations continue to reinforce this shift, with risk analysis failures appearing in nearly every settlement.
- Did you identify risks?
- Did you prioritize them?
- Did you assign ownership?
- Did you remediate them?
- Can you prove you tracked that work over time?
That's called risk management—and it's where many organizations still struggle.
OCR has even signaled that its Risk Analysis Initiative is evolving to explicitly include risk management expectations, not just risk identification.
The Security Risk Assessment Is the Starting Line
I've seen organizations invest significant time and money producing a polished HIPAA Security Risk Assessment—only for it to sit on a shelf.
A risk assessment should never end as a PDF. It should become a living remediation plan—with owners, deadlines, and accountability.
Skipping the assessment altogether is even worse. It leaves you flying blind. You can't effectively prioritize security investments, demonstrate due diligence, or show OCR that you understood and managed your risks before an incident occurred.
And when OCR investigates after a breach, a missing or inadequate Security Risk Assessment is one of the first things they'll examine. Across recent enforcement actions, failure to conduct an accurate and thorough risk analysis has been one of the most common root causes behind settlements and corrective action plans.
We've seen penalties ranging from hundreds of thousands to multi-million-dollar settlements where risk analysis failures were central to the case.
But the financial penalty is only part of the story. The real cost shows up in multi-year corrective action plans, federal oversight, legal expense, operational disruption, and reputational damage that lingers long after the settlement is signed. (legalclarity.org)
The assessment isn't paperwork. It's the foundation of every mature security program.
Compliance Alone Doesn't Stop Breaches
Healthcare has a compliance execution problem.
Security programs succeed when risk assessments become living roadmaps—not annual paperwork exercises.
Every identified risk should translate into prioritized remediation, clear ownership, measurable progress, and regular reporting to leadership.
That's how mature security programs operate.
And increasingly, that's what OCR expects to see.
Healthcare isn't setting records we should be proud of.
If 2025 taught us anything, it's that documenting risk isn't enough anymore.
Managing it is.