Skip to content

What Healthcare Organizations Need Before an OCR Investigation Begins

Posted by Jon-Michael “Jonny” Rosch and Antonina McAvoy in Cybersecurity, Consulting, Risk Advisory, Healthcare.

Key points covered in this article:

  • OCR investigations typically move quickly beyond the triggering incident and focus on whether a healthcare organization can prove it had an effective, documented HIPAA compliance and security program in place beforehand. Key documentation often includes current risk assessments, remediation tracking, policies, training records, business associate agreements, and evidence of ongoing review and oversight.
  • A current HIPAA Security Risk Assessment is the foundation of that readiness. It should reflect the organization’s actual technology environment, identify where ePHI resides, evaluate threats and safeguards, and support a documented risk management process that leadership can use for decision-making and governance.
  • Many healthcare organizations have controls in place but struggle to demonstrate them through current documentation, remediation records, and board-level oversight. Strengthening those areas now can improve regulatory readiness, support cyber resilience, and position the organization to respond more confidently to OCR, insurers, and business partners.

Is Your Healthcare Organization Ready for an OCR Investigation?

When OCR opens an investigation, the focus shifts fast from what happened to whether your organization can prove it had an effective HIPAA compliance program before the incident. For many healthcare organizations, that is where the real challenge begins.

A ransomware attack, lost laptop, employee mistake, or patient complaint can all trigger an investigation by the Office for Civil Rights (OCR). While the event itself may initiate the review, it is rarely the sole focus of the investigation.

Instead, OCR typically wants to understand what your organization had in place before the incident occurred. The conversation quickly shifts from what happened to whether the organization can demonstrate that it had an effective HIPAA compliance and security program before the event occurred. For many healthcare organizations, that is where the real challenge begins.

One of OCR’s First Requests Is Documentation

When OCR opens an investigation, one of its first requests is typically documentation supporting your organization’s compliance with the HIPAA Security Rule. Depending on the circumstances, that may include:
• Current HIPAA Security Risk Assessment (SRA)
• Risk management plan and remediation tracking
• HIPAA security policies and procedures
• Workforce HIPAA and security awareness training records
• Business Associate Agreements (BAAs)
• Incident response policies and documentation
• User access reviews and access control procedures
• Evidence that policies and risk assessments are reviewed and updated regularly

Many organizations have implemented security controls. The challenge is demonstrating that those controls have been consistently documented, maintained, and periodically evaluated over time.

The Security Risk Assessment Is the Foundation

Most covered entities know they are required to perform a HIPAA Security Risk Assessment. OCR guidance on risk analysis helps clarify the expectations for how organizations identify and implement appropriate safeguards, and the Security Risk Assessment (SRA) Tool developed by ONC and OCR can help smaller and medium-sized organizations structure that process.

An effective Security Risk Assessment should do more than identify technical vulnerabilities. It should help leadership understand where electronic protected health information (ePHI) resides, evaluate the threats and vulnerabilities affecting that information, assess the effectiveness of existing safeguards, and prioritize remediation efforts based on risk.

Just as importantly, the assessment should reflect the organization’s current environment. Cloud migrations, acquisitions, new clinical systems, remote work, connected medical devices, and changes in third-party service providers all introduce risks that should be evaluated as part of an ongoing risk management process. Healthcare organizations should also monitor ransomware and cyber extortion activity as part of their broader threat awareness and risk management efforts.

A Security Risk Assessment should be a living management tool, not simply a document prepared to satisfy an annual compliance requirement.

Common Gaps We See

In PBMares’ work with healthcare organizations across the Mid-Atlantic region and beyond, several themes appear repeatedly:
• Security Risk Assessments that have not been updated after significant technology or operational changes.
• Policies and procedures that no longer reflect current practices.
• Workforce training records that are incomplete or inconsistently maintained.
• Risk assessments that identify findings but lack documented remediation plans or evidence that corrective actions were completed.
• Vendor management processes that do not adequately evaluate Business Associates, cloud service providers, or other third-party vendors that create, receive, maintain, or transmit electronic protected health information (ePHI).
• Security controls that exist but are not supported by sufficient documentation.

None of these necessarily indicate poor security. More often, they reflect organizations that have been focused on patient care while governance and documentation have struggled to keep pace with growth, evolving technology, and an increasingly complex threat landscape.

“Healthcare organizations are often doing the right things operationally, but when OCR comes knocking, the question becomes whether they can prove it,” said Antonina McAvoy, Partner in PBMares’ Cybersecurity and Risk Advisory practice. “Documentation and evidence of an ongoing, managed compliance program are what separate organizations that respond confidently from those that scramble.”

Compliance Expectations Continue to Evolve

Healthcare cybersecurity has changed dramatically over the last decade, and regulators are responding accordingly.

In late 2024, the U.S. Department of Health and Human Services (HHS) announced proposed updates to the HIPAA Security Rule designed to strengthen cybersecurity requirements for covered entities and business associates. The proposal emphasizes more robust risk analysis, documented risk management processes, written policies and procedures, stronger contingency planning, regular testing of security controls, and enhanced documentation across the organization. Organizations can also use NIST HIPAA Security Rule guidance and broader security controls testing resources to evaluate whether safeguards are designed and operating effectively.

While the proposed rule has not yet been finalized, it provides valuable insight into the direction of regulatory expectations as organizations prepare for 2027. Organizations that proactively evaluate and strengthen their security programs now will be better positioned to adapt as requirements evolve and demonstrate compliance once new requirements take effect.

Regardless of when the final rule becomes effective, many of the concepts emphasized in the proposal — including comprehensive risk analysis, documented risk management, and ongoing evaluation of safeguards — align with themes OCR has consistently reinforced through investigations and enforcement activities.

Additional information on the proposed updates is available in the official Federal Register publication, HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information.

Beyond Compliance

Today, cybersecurity is increasingly recognized as an enterprise risk management issue rather than solely an IT responsibility. Executive leadership and governing boards are expected to understand the organization’s cybersecurity risks and provide meaningful oversight of HIPAA compliance and risk management activities. Accordingly, a well-executed Security Risk Assessment provides leadership with meaningful insight into the organization’s cybersecurity posture while serving purposes that extend well beyond regulatory compliance. It helps leadership:
• Understand the organization’s cybersecurity risks.
• Prioritize security investments based on risk.
• Support cyber insurance and third-party due diligence requests.
• Demonstrate reasonable and appropriate safeguards.
• Provide meaningful reporting to executive leadership and governing boards.
• Establish a documented roadmap for continuous improvement.

Federal cybersecurity resources increasingly emphasize cybersecurity governance, executive oversight, and risk-informed decision-making as part of a mature cybersecurity program.

“One of the most consistent things we hear from healthcare leadership after going through a thorough risk assessment is that they finally have a clear picture of where they stand,” McAvoy noted. “That clarity has value well beyond regulatory compliance — it shapes smarter investment decisions and gives boards the information they need to provide meaningful oversight.”

For many organizations, the Security Risk Assessment becomes one of the most valuable governance tools available to leadership.

Would Your Organization Be Ready?

Consider the following questions:
• Has our Security Risk Assessment been updated within the past 12 months?
• Does it reflect our current technology environment, including cloud services, remote access, and connected medical devices?
• Are identified risks assigned owners and tracked through remediation?
• Can we demonstrate that identified risks were remediated or formally accepted by management?
• Are HIPAA policies reviewed and updated on a regular basis?
• Could we quickly produce workforce training records if requested?
• Have Business Associate Agreements been reviewed for all applicable vendors?
• Can we demonstrate how leadership oversees cybersecurity and HIPAA compliance?

If several of these questions are difficult to answer, now is an ideal time to evaluate your HIPAA compliance program, before an incident or investigation requires those answers.

Final Thoughts

OCR investigations rarely focus on a single event in isolation. OCR enforcement actions demonstrate that regulators often look at whether an organization has established a reasonable, documented, and continuously managed approach to protecting electronic protected health information.

Organizations that maintain current risk assessments, document their security program, and actively manage identified risks are generally in a much stronger position to respond not only to regulators, but also to cyber insurers, business partners, patients, and governing boards.

Ultimately, a HIPAA Security Risk Assessment should do more than satisfy a regulatory requirement. It should provide leadership with a defensible understanding of the organization’s cybersecurity risks and a practical roadmap for reducing them while strengthening the organization’s overall security posture. Additional resources include: HIPAA Security Rule Proposed Updates (HHS) and  OCR HIPAA Enforcement Actions and Resolution Agreements.

How PBMares Can Help

An effective HIPAA Security Risk Assessment should provide more than a compliance checklist—it should help leadership understand where cybersecurity risks exist, how those risks are being managed, and where investments will have the greatest impact.
PBMares’ Cybersecurity and Risk Advisory professionals combine deep healthcare industry experience with expertise across HIPAA, HITRUST, the NIST Cybersecurity Framework, SOC reporting, and broader cybersecurity risk management. We help healthcare organizations build practical, risk-based compliance programs that strengthen cybersecurity, support regulatory expectations, and improve operational resilience. Whether preparing for an OCR investigation, responding to evolving cybersecurity threats, or strengthening an existing HIPAA compliance program, PBMares helps healthcare organizations validate current practices, identify meaningful gaps, prioritize remediation efforts, and build sustainable compliance programs that withstand regulatory scrutiny while supporting long-term cybersecurity maturity.

To learn more about how PBMares can support your organization’s HIPAA compliance and cybersecurity program, contact our PBMares Healthcare Team, led by Partner Jonny Rosch and Cybersecurity & Risk Advisory Services Partner Antonina McAvoy.


Be sure to consult with your financial or tax advisor on this topic as individual situations may vary. The information contained in this article or webinar, and any related materials, are for informational purposes only, and cannot be relied upon for legal, financial, tax, accounting, or other professional services advice. The content is provided on an “as is” basis and PBMares makes no representations or warranties about the accuracy or sustainability of any information for your purposes. For any specific questions you may have, please contact us.

This content is accurate at the time of publication. Always ensure you are reviewing the most recent information available. Contact your tax or financial advisor if you need clarification.

Contact Us

About the Authors

Antonina McAvoy
Antonina McAvoy

CISA, CISM, QSA, PCIP
Partner, Risk Advisory Services
Norfolk

Antonina McAvoy specializes in cybersecurity, data protection, and privacy. She has 14 years of experience leading and performing a wide spectrum of cybersecurity reviews.

View Bio
Jon-Michael “Jonny” Rosch
Jon-Michael “Jonny” Rosch

CPA
Partner, Healthcare Team Leader
Fairfax

Jonny brings a depth of expertise performing audit and assurance engagements and assisting not-for-profits with complicated accounting and tax issues unique to their industry.

View Bio

Get News, Alerts, and Guidance

PBMares provides timely insights that help businesses build smarter, well-informed strategies. Join them.