What OCR Enforced This Week — and Why “Did You Do the Risk Analysis?” Is Still the First Question

A quiet enforcement week at OCR, but the pattern held: the Risk Analysis is still the first thing investigators ask for.

The short version

It was a quiet week in the OCR newsroom — no new HIPAA breach settlement was posted between September 1 and 11. That is worth noting precisely because the underlying pattern has not gone quiet at all. The most recent resolutions on record still turn on the same two failures OCR has enforced all year: not producing a defensible Security Risk Analysis, and not responding to ransomware exposure that a risk analysis should have surfaced first. A slow news week is a good week to fix the thing that keeps showing up in the fast ones.

Enforcement: what is actually on the record

OCR’s most recent HIPAA settlement remains its Right of Access resolution with Azul Vision (announced late August 2026). The Right of Access Initiative is the agency’s most frequently used enforcement lever, and the lesson is unglamorous: a patient asked for their records, the response fell short, and it became a federal matter. If your organization cannot answer a records request inside the required window, that is an enforcement exposure independent of any breach.

The larger throughline is the Risk Analysis Initiative. OCR’s recent ransomware and health-plan resolutions have repeatedly cited a missing or inadequate risk analysis as the root finding — the initiative has now produced more than a dozen Risk Analysis actions and around twenty ransomware-related actions across its run. The common thread in the settlement language is not “you were breached.” It is “you could not show a current, enterprise-wide analysis of where electronic protected health information lives and how it is exposed.” The breach opens the file; the missing analysis is what OCR names.

Separate from OCR — but instructive — a large private breach settlement moved this week. A multi-million-dollar class-action fund tied to the 2023 LockBit ransomware attack on a dental-benefits administrator (affecting roughly 8.9 million people) reached a claims stage, with an October 2026 deadline for affected individuals. This is litigation, not an OCR action — we flag it because it shows the second bill after a breach. The vendor was a business associate; the exposure ran through it to the health plans and members it served. Third-party risk is not a side channel to HIPAA liability. It is the main channel.

Breach portal: read the trend, not just the week

The HHS breach portal (the public list of reported breaches affecting 500 or more individuals) did not surface a confirmed new large healthcare posting in this specific window through the tools available to us, and we do not publish individual counts we cannot independently confirm. The aggregate picture, refreshed in early September from OCR data, is the more useful read anyway: hacking and IT incidents continue to account for the overwhelming majority of reported breaches and of individuals affected, and business-associate incidents remain a disproportionate share of the largest events. If you are budgeting attention, that is where it goes — external intrusion and vendor exposure, not lost laptops.

The 2026 Security Rule: still proposed, now expected later

For anyone being told they must comply with “the new 2026 HIPAA Security Rule”: that rule is still a proposal. The Notice of Proposed Rulemaking published in January 2025, the comment period closed in March 2025, and OCR is still working through several thousand public comments. The timeline has slipped — a final rule is not expected before 2027 on current federal agendas, and more than a hundred hospital systems and provider associations have formally asked HHS to withdraw or substantially revise it. Nothing about that status changed this week.

What that means practically: do not re-architect your program around proposed language that may change or may not finalize. But also do not use “it is only proposed” as a reason to stand still. Almost everything the proposal would tighten — an annual, documented risk analysis; asset and data-flow inventories; encryption and multi-factor authentication as expectations rather than options — is already how OCR reads the current rule when it investigates. The proposal mostly writes down what enforcement already assumes. Get current on today’s Security Rule and the proposed one holds few surprises.

What to do with a quiet week

  1. Confirm your Security Risk Analysis is current, enterprise-wide, and documented. Not a checklist someone completed once — an analysis that names where ePHI lives across every location and system, rates the risks, and ties to a remediation plan you are actually working. This is the single artifact OCR asks for first.
  2. Pull your business associates into the same frame. Know which vendors touch ePHI, that a signed BAA exists for each, and that you have some basis beyond their word for trusting their security. The largest breaches keep arriving through vendors.
  3. Close the Right of Access gap. Make sure records requests are logged, tracked, and answered inside the window. It is the most-enforced HIPAA obligation and the easiest to get wrong quietly.

Medcurity’s Security Risk Analysis is built for exactly the artifact OCR asks for first — a guided, defensible, multi-site analysis with expert review and a tracked remediation plan, mapped to recognized NIST guidance. If a quiet enforcement week is a chance to get ahead of a loud one, this is where to start.

This digest is compiled from public HHS OCR newsroom postings, the HHS breach reporting portal, and HIPAA compliance press for the week ending September 11, 2026. Where an individual breach count could not be independently confirmed, it is described qualitatively rather than stated as a figure.