How OCR gets involved
The Office for Civil Rights within HHS enforces HIPAA's privacy, security, and breach notification rules. Its involvement usually starts with a complaint from a patient or employee, a breach report the organization itself filed, or a compliance review prompted by news coverage or a pattern of reports. Breaches affecting large numbers of people must be reported to HHS promptly and are posted publicly, while smaller ones are reported on a periodic basis. State attorneys general can also enforce HIPAA, and they often bring state law claims alongside it. HIPAA regulatory affairs therefore involves more than one regulator, even when the incident is the same.
Responding to a data request
OCR typically asks for policies, risk analyses, training records, and documents about the specific incident or complaint. The risk analysis is often central, and an outdated or incomplete one is among the findings that appear most often in enforcement actions. Respond accurately and on time, and do not present documents created after the fact as if they existed before. Where gaps exist, it is usually better to explain them and show what has been done to close them. Coordinate the response with any state notification, insurer, and litigation obligations so the organization tells a consistent story.
Resolution and what comes after
Many OCR matters close with technical assistance or without findings, but others end in a resolution agreement that includes a payment and a corrective action plan monitored over time, or in civil money penalties. The terms of a corrective action plan can shape privacy and security work for an extended period, so they deserve negotiation. We review the request, the incident history, and the current state of your compliance documents before the response is drafted. We also discuss how to present remediation already underway. Afterward, the work turns to meeting the commitments made to the agency.