Skip to main content
CoreFolioHIPAA

CoreFolio Learn

Enforcement

What OCR is actually investigating right now, and how small practices end up on the wrong end of a settlement.

The OCR Risk Analysis Initiative, explained

OCR is now investigating small practices that have never had a breach — because they never did a risk analysis. Here is what changed in late 2024, what the rule actually requires, and what a defensible answer looks like.

12-minute read

What OCR actually wants in a risk analysis

HHS's Office for Civil Rights has now settled with dozens of practices for risk analysis failures. The pattern in their investigation letters and resolution agreements tells you exactly what they are looking for.

5-minute read