HIPAA Tip: HHS OCR HIPAA Enforcement
You need me – oh yes you do! Every OCR breach investigation in 2026 cited the failure to conduct an accurate and thorough HIPAA Security Risk Analysis (SRA).
It’s not good enough to put together a HIPAA compliance policy and procedure manual, put it on a shelf, never share with staff or update policies and procedures specific for the organization. Changes occur all the time within the business environment and must be current, reflecting what is expected of staff and how security operations are in place.
PHI and ePHI must be identified: how is the data secured, where does the data flow throughout the organization and outside the confines of the business. ePHI can be in a web-/cloud-based solution, on medical devices, commercial copiers, on servers onsite, and on computers on the local drives? What about Business Associates? Are they storing PHI/ePHI for the institution?
Only looking at the technical securities when conducting a SRA is not good enough. The Administrative, Physical and Technical Safeguards and the Implementation Specifications for these safeguards must be addressed.
Contact a HIPAA expert to conduct a comprehensive SRA and educate your business on HIPAA requirements.
Compliance Is Ongoing
HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.