There's a particular kind of frustration that healthcare IT and compliance officers know well: the kind that comes from being asked to prepare for something that may or may not happen, on a timeline that keeps shifting, under cost assumptions that bear no relationship to reality. That's the situation right now with federal healthcare cybersecurity regulation, and if you've been getting emails from vendors suggesting you're already out of compliance with new HIPAA security rules, you should know: you're not. Not yet. Maybe not ever, at least not in the form currently proposed.
Here's what's actually happening.
OCR's New Focus: Risk Management, Not Just Risk Analysis
On April 8th, OCR's Senior Advisor for Cybersecurity Nick Heesters released a guidance video that every HIPAA-regulated entity should watch. In it, he makes clear that the agency has formally expanded its enforcement initiative beyond risk analysis to include risk management: what organizations actually do about the risks they find. If you take one thing from OCR's recent activity, it's this: knowing your risks is no longer enough. Acting on them is now what the agency is enforcing.
Risk Analysis
- Identifies vulnerabilities and threats
- A point-in-time snapshot
- Documents what could go wrong
Risk Management
- Acts on the risks that were identified
- A continuous, ongoing program
- Proves what was actually done
The pattern OCR keeps finding isn't organizations that don't know their risks. It's organizations that document them, and then do nothing. In investigation after investigation, OCR has found the same vulnerabilities appearing in security reviews year after year, unmitigated, until they were finally exploited.
"Failing to take action to mitigate risks or implementing security measures that do not sufficiently reduce risks to a reasonable and appropriate level is something OCR discovers frequently." Nick Heesters, Senior Advisor for Cybersecurity, OCR
The breach data explains why OCR is pressing this. In 2024, large HIPAA breaches affected more than 286 million individuals. In 2025, 76% of large breaches were caused by hacking and IT incidents. These are not surprises — they are, in OCR's framing, "reasonably anticipated" threats that obligate regulated entities to act.
One more thing to understand about the legal standard: policies and written plans are not enough.
"Policies and procedures alone are not sufficient evidence of security measure implementation," Heesters said. OCR wants to see that identified risks drove real decisions — configurations changed, controls validated, measures actually in place. The question regulators are now asking isn't just "did you find the risks?" It's "what did you do about them, and can you prove it?"
Organizations that fall short face a finding of willful neglect (the most serious HIPAA violation category) carrying penalties of $73,011 per day, per violation.
What to Do Right Now: Build a Program, Not a Checklist
The regulatory picture may be unsettled, but the operational imperative isn't. Whether the NPRM is finalized, revised, or rescinded, OCR is actively enforcing the rules that exist today — and the bar it's applying is whether your organization has a functioning, continuous risk management program. Not a point-in-time assessment. Not a binder of policies. A living program.
That starts with knowing your assets. You cannot manage risk to electronic protected health information you haven't fully accounted for. Every system, application, device, and data flow that touches ePHI needs to be in scope — including the ones that have been quietly accumulating through acquisitions, new vendors, and technology changes. Gaps in asset inventory are gaps in your risk picture, and gaps in your risk picture are exactly what OCR finds when things go wrong.
From there, the risk analysis has to be thorough and honest. Federally recognized frameworks (NIST CSF 2.0, NIST SP 800-66, and the HHS 405(d) Health Industry Cybersecurity Practices) exist precisely to give organizations a structured, defensible methodology for this work. They don't prescribe a single path, but they provide the architecture for one. Using them isn't just good security hygiene; it's the kind of documented, principled approach that holds up under regulatory scrutiny.
But the analysis is only the beginning. What OCR is now demanding (and what the breach data makes painfully clear is necessary) is that identified risks are actually managed over time. That means prioritizing findings, implementing controls, validating that they work, and revisiting the program as your environment changes. New technology, new vendors, new threats: each one is a reason to update your risk picture, not a reason to wait for the next scheduled assessment.
Done well, this isn't just a compliance exercise. It's the foundation of operational resilience: the difference between an organization that discovers a vulnerability in a review and one that discovers it in a breach notification.
Healthcare organizations carry a profound responsibility to the patients they serve. A continuous, enterprise-wide risk management program is how you fulfill that responsibility and demonstrate, credibly, that you've done everything in your power to protect them.
The good news is the frameworks are there, the guidance is clear, and OCR has been remarkably transparent about exactly what it's looking for. The work is hard, but it isn't mysterious.
Common questions on HIPAA Security Rule enforcement
Is the HIPAA Security Rule overhaul final?
No. HHS has pushed final action to at least July 2027 on its updated federal agenda. The proposal is delayed, not shelved, and many observers expect it to slip further.
What is OCR focused on enforcing right now?
OCR has formally expanded its enforcement initiative beyond risk analysis to include risk management: what organizations actually do about the risks they identify, not just whether they found them.
Are written HIPAA policies enough to satisfy OCR?
No. OCR's Nick Heesters has stated that policies and procedures alone are not sufficient evidence of security measure implementation. OCR wants proof that identified risks drove real decisions and changes.
What penalty applies to willful neglect under HIPAA?
Willful neglect is the most serious HIPAA violation category and carries penalties of $73,011 per day, per violation.
What frameworks can organizations use for HIPAA risk analysis?
NIST CSF 2.0, NIST SP 800-66, and the HHS 405(d) Health Industry Cybersecurity Practices all provide federally recognized, structured methodologies for a defensible risk analysis.
Have Questions? Clearwater Can Help.
Clearwater has spent two decades helping healthcare organizations build the kind of enterprise-class risk management programs that hold up under OCR scrutiny, and in every OCR investigation involving a Clearwater risk analysis, the outcome has been successful. Whether you're starting from scratch, pressure-testing an existing program, or trying to make sense of a shifting regulatory landscape, our team is here.
Contact Us


