OCR audited 166 covered entities and 41 business associates across 2016 and 2017, reviewing their documentation against selected provisions of the Privacy, Security, and Breach Notification Rules. Compliance was rated on a five-point scale, where 1 meant the entity met the goals of the standard and 5 meant no evidence of a serious attempt to comply. The Industry Report OCR published in December 2020 covers seven areas and organizations demonstrated general compliance in two of them.
Risk analysis: 14%
14% of covered entities and 17% of business associates substantially fulfilled their responsibility to conduct an accurate and thorough risk analysis. The remainder produced something incomplete, outdated, or nothing at all. That single number explains most of what OCR has done since. The agency's Risk Analysis Initiative, which by June 2026 had produced 14 enforcement resolutions alongside 20 total ransomware actions, targets the precise failure the audits measured. Paubox's mid-year breach analysis separately cited OCR enforcement data finding inadequate enterprise-wide risk analysis in more than 75% of resolution agreements involving security incidents from 2020 to 2024.
Risk management: 6%
Risk analysis identifies problems. Risk management fixes them, and the audits found 6% of covered entities and 12% of business associates implementing risk management activities sufficient to reduce vulnerabilities to a reasonable level.
Read alongside the risk analysis figure, the sequence gets worse rather than better. A minority of organizations assessed their risks, and a minority of that minority acted on what they found. Analysis of the report by Bricker Graydon recorded 94% of covered entities and 88% of business associates failing this requirement outright.
Notice of Privacy Practices content: 2%
2% of covered entities fully met the content requirements for a valid Notice of Privacy Practices. National Law Review's analysis noted that two-thirds either failed or made minimal efforts, with most omissions involving required content about individual rights, and some notices failing the plain language requirement. This is the least technical obligation in the entire Privacy Rule. It requires no configuration, no vendor, and no budget, which makes a 2% pass rate difficult to attribute to resource constraints.
Individual right of access: 11%
89% of audited covered entities failed to demonstrate they were correctly implementing the individual right of access, covering timely action within 30 days and charging a reasonable cost-based fee. OCR had already made this an enforcement priority, settling 12 cases under its Right of Access initiative during 2020 alone. Then OCR Director Roger Severino tied the audit findings directly to that program, stating enforcement would continue "until health care entities get serious about identifying security risks."
Breach notification timeliness: one of two passes
Most covered entities met the 60-day requirement for notifying individuals after a breach. Alongside prominently posting a Notice of Privacy Practices on a website, this was one of only two areas where OCR found general compliance. Both passes share a characteristic as they are deadline-driven or one-off tasks with a clear completion point, rather than ongoing practices requiring maintenance.
Breach notification content: 33%
76% of covered entities failed to document adequate compliance with the content requirements for breach notification letters. OCR listed what was most frequently missing:
- A description of the types of unsecured PHI involved.
- Steps individuals should take to protect themselves from harm.
- Adequate contact information.
- An explanation of the entity's own investigation and mitigation activity.
Organizations sent letters on time, and those letters did not tell patients what had happened to their data or what to do about it.
How the audits took place
These were desk audits, meaning remote reviews of submitted documentation rather than site visits. Entities were selected randomly across a geographic cross-section including practitioners, pharmacies, hospitals, health systems, skilled nursing facilities, and elder care facilities. Business associates were drawn from lists the audited covered entities supplied.
No breach triggered these reviews nor was OCR investigating incidents, and the organizations audited were not selected because anything had gone wrong. The findings describe the baseline condition of healthcare compliance rather than the condition of organizations that had already failed.
The gap this opens against how leaders see themselves
Paubox asked healthcare IT leaders how confident they were in preventing email-based data breaches, and 92% said they were confident. The same survey found 8 in 10 admitting they worry about their HIPAA compliance status and 86% reporting that their email security tools cause workflow friction.
Set the 92% against OCR's 6% on risk management, and the distance is hard to close through interpretation. What the audits suggest is that confidence tracks what organizations have been told rather than what has been verified, and the verification only happens when somebody external asks for the documentation.
What OCR is doing now
The agency began a new round of HIPAA audits covering 2024 and 2025, focused on Security Rule compliance, and has committed to publishing an industry report once they conclude. Selected entities receive OCR's assessment of their compliance in the reviewed provisions alongside guidance on improving their ePHI security.
The questions are not confidential, but there are many; OCR publishes its Audit Protocol, organized by rule and regulatory provision, covering roughly 180 areas of potential inquiry. For each provision, it specifies what an organization must demonstrate, what documentation OCR requests, and how the evidence gets evaluated. Document requests cover versions in use as of the audit notification date, and where documentation does not exist, the entity must submit a statement saying so.
Where email sits in this and how we can help
Risk analysis has to cover every system touching ePHI, which includes the mail platform and any add-on handling patient data. Risk management means acting on what that analysis surfaces. Breach notification content requires describing what data was involved, which demands records of what was transmitted and whether it was protected.
Controls that operate identically on every message produce that evidence as a byproduct. Paubox Email Suite encrypts every outbound message by default, so the answer to whether encryption applied does not vary by sender or by day. Paubox Archiving retains the record an auditor asks for. Paubox Inbound Email Security reads sender behavior and message intent before delivery, addressing the entry point most enforcement actions eventually trace back to.
In the news
The requirements themselves may change before the next report lands. HHS published a Notice of Proposed Rulemaking in December 2024 proposing the first major Security Rule overhaul in more than a decade, and one provision speaks directly to the 6% finding. The proposal removes the distinction between required and addressable implementation specifications, which currently permits an organization to document a rationale for not implementing encryption or multi-factor authentication. Under the proposal, both become mandatory, which converts a judgment call into a binary the audits can test. A second provision requires a maintained technology asset inventory covering every piece of software touching ePHI, addressing the scope failures that make a risk analysis inadequate; however, the rule still remains under review.
FAQs
Were these audits triggered by breaches?
No. OCR selected entities randomly across a geographic cross-section, and the audits were compliance reviews rather than investigations. The findings describe healthcare's general baseline rather than organizations already known to have failed.
What is the difference between risk analysis and risk management?
Risk analysis identifies threats to the confidentiality, integrity, and availability of ePHI across every system holding it. Risk management is acting on those findings to reduce the risks to a reasonable level. OCR found 14% substantially fulfilling the first and 6% the second.
Why did so few organizations pass the Notice of Privacy Practices requirement?
Only 2% met the full content requirements, with most omitting required information about individual rights and some failing the plain language standard. The obligation needs no technology or budget, which makes the result harder to explain through resource constraints.
Can we see what OCR will ask us?
Yes. The Audit Protocol is published on the HHS website, organized by rule and provision across roughly 180 inquiry areas, specifying what must be demonstrated and what documentation is requested for each.
Are more audits happening?
OCR began a round covering 2024 and 2025 focused on Security Rule compliance, with an industry report promised once they conclude.
