HEALTHCARE COMPLIANCE
What Is OCR (HHS Office for Civil Rights)?
DEFINITION
OCR (the HHS Office for Civil Rights) is the federal agency that enforces the HIPAA Privacy, Security, and Breach Notification Rules. It investigates complaints and reported breaches, conducts compliance reviews, and resolves violations through settlements, corrective action plans, and civil money penalties against covered entities and business associates that fail to protect health information.
OCR sits within the US Department of Health and Human Services and is the primary HIPAA enforcement authority. Its caseload comes from individual complaints, breach reports filed by covered entities and business associates, and compliance reviews it opens on its own initiative. Investigations typically begin with a data request that asks for the organization's risk analysis, policies, and training records, and they can end in technical assistance, a resolution agreement with a multi-year corrective action plan, or civil money penalties.
Every HIPAA covered entity and business associate is within OCR's reach, from solo practices to national health systems and their technology vendors. Breaches affecting 500 or more individuals draw particular scrutiny because they are publicly reported and routinely trigger an investigation.
The practical implication is that OCR enforcement is currently concentrated on one question: can you produce an accurate, current risk analysis? OCR's Risk Analysis Initiative is actively generating settlements on that issue, including four ransomware-related settlements announced in April 2026. Organizations that cannot answer that question should start with a documented security risk assessment and work through a HIPAA Security Rule compliance checklist before an investigator asks first.
Running a program that has to satisfy this?
A Z Cyber advisor can walk your current posture against the requirement and show you what a running program looks like on Glance.
Meet Your Security Team →