Will OCR Accept Your HIPAA Security Risk Analysis?

OCR is the HHS Office for Civil Rights — the federal regulator that investigates HIPAA complaints and breaches and enforces the Security Rule. When OCR opens an investigation, the first document request is almost always the same: show us your Security Risk Analysis.

At that moment, “we did one” is not the question. The question is whether the document you hand over demonstrates an “accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information” — the exact standard at 45 CFR §164.308(a)(1)(ii)(A). It is a Required implementation specification, not an addressable one. And in enforcement action after enforcement action, the SRA is where organizations fail.

The question OCR is actually asking

OCR does not grade your security. It grades your analysis. An organization with imperfect controls and an honest, thorough, tracked risk analysis is in a defensible position. An organization with decent controls and a checklist stapled to a template is not. The distinction runs on a few tests:

  • Is it yours? A template someone filled in generically fails the “accurate” half of the standard. The analysis must reflect your actual systems, your actual sites, your actual vendors.
  • Is it complete? Every system that stores, processes, or transmits ePHI belongs in scope — including the vendors who touch it. Incomplete asset inventories are among the most common deficiencies cited in resolution agreements.
  • Does it cover the physical world? The Security Rule’s physical safeguards at 45 CFR §164.310 — facility access controls, workstation security, device and media controls — apply to your actual buildings. A remote questionnaire cannot see a propped server-room door, a check-in screen facing the waiting room, or the departed employee’s laptop nobody collected. If your SRA was done entirely from a desk, §164.310 is where it is thinnest.
  • Did a human exercise judgment? “Accurate and thorough” is a judgment standard. Software can organize the work; it cannot certify that the conclusions are sound. Someone qualified has to look at the whole analysis and be willing to stand behind it.
  • Is it alive? A PDF from last year with no remediation trail reads as a checkbox. OCR expects prioritized findings with owners, deadlines, and progress — evidence that risk management is ongoing, not annual.

For the full criteria breakdown, see What OCR Looks For in a HIPAA SRA and what “OCR-ready” actually means.

What a 100% acceptance rate means

Every Medcurity Security Risk Analysis presented to the HHS Office for Civil Rights has been accepted — a 100% acceptance rate. No other platform in this category publishes its OCR outcomes.

That outcome is not luck. It is the direct product of how the analysis is built:

  • Human expert review of every guided SRA. HIPAA experts review each guided Security Risk Analysis before it is finalized — the judgment step §164.308(a)(1)(ii)(A) implicitly requires, built into the process rather than left to hope.
  • Onsite §164.310 assessment. A Medcurity assessor evaluates physical safeguards at your actual facilities, so the section most desk-based SRAs skim is documented from direct observation.
  • A methodology, documented. Risks are scored by likelihood and impact within a consistent framework, so when an investigator asks why a risk was rated high, the answer is the framework — not intuition.
  • A living remediation record. Findings land on a worklist with owners and deadlines; the SRA you hand OCR comes with the ongoing-management evidence attached.
  • A named advisor, year-round. Between assessments, your advisor keeps the program moving — so next year’s analysis shows what changed, what improved, and what new risks emerged.

The test to run before OCR runs it

Ask three questions of your current SRA today:

  1. If OCR asked why a specific risk was scored the way it was, could you point to a documented methodology?
  2. Could you produce the remediation status of your top five findings — owner, deadline, progress — in one afternoon?
  3. Has anyone physically walked your facilities against §164.310 since the last assessment?

If any answer is no, the gap is fixable — and far cheaper to fix before an investigator finds it. Weak or missing risk analyses have driven OCR settlements commonly reaching six figures per investigation, and OCR’s Risk Analysis Initiative has made the SRA itself the center of current enforcement.

Get an SRA built to be accepted

Medcurity has served 1,000+ healthcare organizations since 2018 — rated 4.92/5 — from small practices (transparent entry at $499/year for practices under 20 staff) to multi-site health centers and hospitals from 50 to 5,000+ employees. Talk to our team and we will show you exactly what an audit-defensible SRA looks like for your organization.