On April 23, 2026, the HHS Office for Civil Rights settled four ransomware investigations in a single announcement: $1,165,000 in penalties, more than 427,000 patients affected, and a two-year corrective action plan attached to every one of them. Regional Women's Health Group, Assured Imaging, Consociate Health, and a self-insured health plan run by Star Group, L.P. Different sizes, different states, different attack paths. Same finding underneath: none of them had closed the loop between knowing about a risk and doing something about it.
I have spent more than two decades building and defending healthcare security programs, and this is the most consequential shift in HIPAA enforcement I have watched happen in real time. OCR used to ask a binary question: did you conduct a risk analysis. Now it asks a harder one: what did you do with what the analysis told you.
Understanding What OCR Is Really Testing
The HIPAA Security Rule has always had two distinct obligations sitting next to each other. Risk analysis, under 45 CFR 164.308(a)(1)(ii)(A), requires an accurate and thorough assessment of risks to electronic protected health information. Risk management, under 164.308(a)(1)(ii)(B), requires implementing measures sufficient to reduce those risks to a reasonable level. That second obligation has been in the rule since 2003. OCR simply did not enforce it with any consistency for two decades.
That has changed. Thirteen resolutions have now come out of OCR's Risk Analysis Initiative, and the deficiency findings in the April batch read less like "you never looked" and more like "you looked, you wrote it down, and you didn't act." Consociate Health's breach traced back to an exploited phishing vulnerability, the kind of gap a risk analysis is built to surface. The organization's failure was not ignorance. It was inaction.
Here is the part worth sitting with before drawing the wrong lesson from it. Assured Imaging never conducted a compliant risk analysis at all, and it paid the largest penalty of the four, $375,000. So the honest reading is not that a documented, unremediated finding is worse than no analysis whatsoever. The data does not support that ranking. What it supports is narrower and, I think, more useful: a risk register with open, aging findings no longer functions as a mitigating factor. It used to buy an organization some credit, evidence of good-faith effort even if the program was imperfect. That credit is gone. A stale register now proves the organization had actual knowledge of the gap and chose not to close it, which is a stronger evidentiary position for OCR than an organization that can at least claim it never knew.
A smoke detector that never gets a new battery is not safety equipment anymore. It is a liability with a chirp.
Why This Isn't New Law, Just Enforced Law
Some of you are waiting for the proposed HIPAA Security Rule update, the one that would spell out specifics like patch timelines, mandatory multifactor authentication, and vulnerability scanning cadence. I would stop waiting. That rule was originally targeted for finalization in 2026. It has now slipped to roughly July 2027, and the administration has signaled it may revisit the burden of some proposed changes before finalizing anything.
OCR is not sitting on its hands until that rule lands. It is enforcing the risk management standard that has existed since 2003, using the current rule text, years ahead of the amendment that would make the expectation explicit. Do not build your remediation program around what the final rule might eventually require. Build it around what OCR is already penalizing today.
Two other assumptions deserve to be retired alongside it. The first is that this only touches large health systems. The smallest breach in the April batch affected 9,316 individuals, a health plan, not a hospital, and it still drew a $245,000 penalty and a two-year CAP. The second is that this is a covered-entity problem. OCR has already brought Risk Analysis Initiative actions directly against business associates. If you are a vendor, an MSP, or a platform serving healthcare, this initiative reaches you directly, not through your customer's contract.
What Closes The Loop
A finding without an owner is not a finding. It is a note to self that a regulator can later read as a confession. Closing the loop means three things, consistently applied:
- Assign a named owner to every finding. Not a department, not "IT." A person whose name is on the remediation item and whose job includes seeing it through.
- Attach a real deadline and track it at the executive level. A finding that sits in a spreadsheet for eighteen months with no target date is functionally identical, to an investigator, to a finding that was never identified.
- Keep evidence of closure, not just intent. A patched system, a signed sign-off, a retest result. "We planned to fix it" is not remediation. It is a plan, and plans do not show up as mitigating evidence in a CAP negotiation.
There is one lever in current law that rewards exactly this kind of discipline, and I do not see enough organizations using it. Under the HITECH Section 13412 amendment, OCR is required to consider whether an entity has maintained recognized security practices, such as the NIST Cybersecurity Framework or the HITRUST CSF, for the twelve months preceding an incident. It is not a safe harbor. It does not excuse an unremediated finding. But it can shorten an investigation and narrow a CAP, and it is the closest thing to a mitigating credit that current law offers. If your organization has invested in a recognized framework, make sure that investment is documented well enough to be presented as evidence, not just referenced as a slide in a board deck.
The Case For Acting Now
None of this changes what good security programs were already supposed to be doing. It changes what happens to the ones that were not. A risk register with open findings and no remediation trail is no longer a sign that your program is a work in progress. It is a paper trail showing exactly what you knew and exactly when you knew it.
The organizations in that April 23 announcement did not lack awareness. They lacked follow-through. That is a fixable problem, and it is a far cheaper one to fix in the second quarter of this year than after the next investigation opens.
Sources:
- HHS Office for Civil Rights, "OCR Settles Four Ransomware Investigations"
- TechTarget, "OCR settles four HIPAA investigations, prioritizes risk analysis"
- Nixon Peabody, "Ransomware enforcement update: 19 investigations completed by OCR, four settlements added"
- HIPAA Journal, "Final Rule Implementing HIPAA Security Rule Updates Edges Closer"
- Wyrick Robbins, "OCR Kicks Off 2025 with Two New HIPAA Enforcement Actions Against Business Associates"