Will OCR Accept Your HIPAA Security Risk Analysis?
OCR is the HHS Office for Civil Rights — the federal
regulator that investigates HIPAA complaints and breaches and enforces
the Security Rule. When OCR opens an investigation, the first document
request is almost always the same: show us your Security Risk
Analysis.
At that moment, “we did one” is not the question. The question is
whether the document you hand over demonstrates an “accurate and
thorough assessment of the potential risks and vulnerabilities to the
confidentiality, integrity, and availability of electronic protected
health information” — the exact standard at 45 CFR
§164.308(a)(1)(ii)(A). It is a Required implementation specification,
not an addressable one. And in enforcement action after enforcement
action, the SRA is where organizations fail.
The question OCR is
actually asking
OCR does not grade your security. It grades your analysis.
An organization with imperfect controls and an honest, thorough, tracked
risk analysis is in a defensible position. An organization with decent
controls and a checklist stapled to a template is not. The distinction
runs on a few tests:
- Is it yours? A template someone filled in
generically fails the “accurate” half of the standard. The analysis must
reflect your actual systems, your actual sites, your actual
vendors. - Is it complete? Every system that stores,
processes, or transmits ePHI belongs in scope — including the vendors
who touch it. Incomplete asset inventories are among the most common
deficiencies cited in resolution agreements. - Does it cover the physical world? The Security
Rule’s physical safeguards at 45 CFR §164.310 — facility access
controls, workstation security, device and media controls — apply to
your actual buildings. A remote questionnaire cannot see a propped
server-room door, a check-in screen facing the waiting room, or the
departed employee’s laptop nobody collected. If your SRA was done
entirely from a desk, §164.310 is where it is thinnest. - Did a human exercise judgment? “Accurate and
thorough” is a judgment standard. Software can organize the work; it
cannot certify that the conclusions are sound. Someone qualified has to
look at the whole analysis and be willing to stand behind it. - Is it alive? A PDF from last year with no
remediation trail reads as a checkbox. OCR expects prioritized findings
with owners, deadlines, and progress — evidence that risk management is
ongoing, not annual.
For the full criteria breakdown, see What OCR Looks
For in a HIPAA SRA and what “OCR-ready”
actually means.
What a 100% acceptance rate
means
Every Medcurity Security Risk Analysis presented to the HHS
Office for Civil Rights has been accepted — a 100% acceptance
rate. No other platform in this category publishes its OCR
outcomes.
That outcome is not luck. It is the direct product of how the
analysis is built:
- Human expert review of every guided SRA. HIPAA
experts review each guided Security Risk Analysis before it is finalized
— the judgment step §164.308(a)(1)(ii)(A) implicitly requires, built
into the process rather than left to hope. - Onsite §164.310 assessment. A Medcurity assessor
evaluates physical safeguards at your actual facilities, so the section
most desk-based SRAs skim is documented from direct observation. - A methodology, documented. Risks are scored by
likelihood and impact within a consistent framework, so when an
investigator asks why a risk was rated high, the answer is the framework
— not intuition. - A living remediation record. Findings land on a
worklist with owners and deadlines; the SRA you hand OCR comes with the
ongoing-management evidence attached. - A named advisor, year-round. Between assessments,
your advisor keeps the program moving — so next year’s analysis shows
what changed, what improved, and what new risks emerged.
The test to run before OCR
runs it
Ask three questions of your current SRA today:
- If OCR asked why a specific risk was scored the way it was,
could you point to a documented methodology? - Could you produce the remediation status of your top five findings —
owner, deadline, progress — in one afternoon? - Has anyone physically walked your facilities against §164.310 since
the last assessment?
If any answer is no, the gap is fixable — and far cheaper to fix
before an investigator finds it. Weak or missing risk analyses have
driven OCR settlements commonly reaching six figures per investigation,
and OCR’s Risk Analysis Initiative has made the SRA itself the center of
current enforcement.
Get an SRA built to be
accepted
Medcurity has served 1,000+ healthcare organizations since 2018 —
rated 4.92/5 — from small practices (transparent entry at $499/year for
practices under 20 staff) to multi-site health centers and hospitals
from 50 to 5,000+ employees. Talk to our team and we will
show you exactly what an audit-defensible SRA looks like for your
organization.