A Quiet but Significant Shift
The Office for Civil Rights launched its Risk Analysis Initiative at the end of 2024 with a narrow, almost mechanical question: did this organization conduct an accurate and thorough analysis of the risks to its electronic protected health information? If the answer was no, a settlement followed. Dozens of them have, and the pattern has been consistent enough that we wrote about the violations behind the fines earlier this year.
The agency has now signaled that the initiative is evolving from risk analysis to risk management. The distinction sounds academic. It is not. It is the difference between "show me your document" and "show me what changed because of your document."
Why This Is a Much Harder Test
A risk analysis is a snapshot. You can commission one, file it, and produce it on request. Plenty of organizations have done exactly that, and until recently it was often enough to satisfy the first question an investigator asked.
Risk management is a record of behavior over time. To demonstrate it, you have to show that identified risks were prioritized, that someone was assigned to each one, that remediation happened or a documented decision was made to accept the risk, and that the whole loop was revisited when things changed. That is not a document. It is a habit with a paper trail.
Here is the uncomfortable part. The Security Rule has always required both. Risk analysis and risk management are separate, named implementation specifications, and the second one has been sitting right there next to the first since 2003. The initiative's first phase simply started with the easier question. Nothing new is being asked of you; a requirement that was under-enforced is being enforced.
What "Acting On It" Looks Like in Practice
If an investigator asked you today to show what you did about last year's findings, what would you hand over? These are the artifacts that answer that question well:
- A remediation register, not a report appendix. Each identified risk gets a row: what it is, how severe, who owns it, what the target date was, what actually happened, and when. A spreadsheet is fine. A report that ends with "recommendations" and nothing after it is not.
- Evidence that the work happened. A ticket, a change record, a screenshot of the setting, an invoice for the encryption software. "We fixed it" is an assertion; the artifact is the proof.
- Documented risk acceptance where you chose not to act. This is legitimate and expected — not every risk justifies its remediation cost. What makes it defensible is that a named person with authority made the call, in writing, with a rationale and a review date. What makes it indefensible is silence.
- Dates that move. A register where every item is still "in progress" eighteen months later tells its own story. So does one where the same five risks reappear in three consecutive analyses.
- A trigger for re-analysis. New EHR, new location, new remote-work arrangement, a merger, a breach — each should start the loop again. An annual cadence with no event-driven triggers means your analysis is stale the moment anything changes.
The Gap Most Practices Have
In our experience the risk analysis usually exists. Someone paid for it, it is thorough enough, and it is filed where it can be found. The gap opens immediately after. The findings were never converted into owned, dated work, so there is nothing to show for the twelve months that followed.
That gap is not evidence of a careless practice. It is what happens when the analysis is treated as the deliverable rather than as the input. The report arrives, it is long, it is discouraging, and it goes in a drawer — and the next annual report finds the same issues, which is the clearest possible signal that no management loop exists.
A Reasonable Way to Close It
You do not need a governance framework to fix this. You need three things, and you can start them this week.
One: pull the findings out of the report and into a list. Strip out the narrative. What remains is usually fifteen to forty discrete items. That list is now your working document; the report becomes the reference.
Two: assign every item an owner and a date. Owners are people, not departments. If one person owns everything, the real number of items you can close this quarter is small — say so explicitly and sequence them rather than pretending otherwise.
Three: hold a thirty-minute review on a recurring schedule. Quarterly is enough for most practices. The only agenda is: what closed, what slipped, what is new, what are we formally accepting. Keep the minutes. Those minutes are, on their own, better evidence of risk management than most organizations can currently produce. Our 90-minute quarterly mini-audit is a ready-made structure for it.
Why This Is Worth Getting Ahead Of
Enforcement initiatives tend to broaden, not narrow. The first phase established that a missing risk analysis is an easy finding; the second establishes that an unactioned one is too. An organization that can produce a register, evidence, and meeting minutes answers the harder question immediately and moves the conversation on. An organization that can only produce a report is answering the question that stopped being the whole question.
And the security benefit is not incidental. The practices that close findings on a schedule are, unsurprisingly, the ones with fewer findings to close next year.
Related Reading
- 8 signs your HIPAA risk assessment is actually worthless
- 9 things OCR auditors actually ask for
- The 90-minute quarterly HIPAA mini-audit
- The HIPAA risk assessment, explained
Call to Action
If your last risk analysis is sitting in a drawer, the fix is smaller than it feels. Schedule a walkthrough to see how findings, owners, due dates, and evidence stay in one place instead of in a PDF — or take the 3-minute readiness quiz to see where you would stand if someone asked today.