Every large OCR penalty tells the same story in its first paragraph: a breach happened, the investigation opened, and the entity could not produce a current, enterprise-wide risk analysis. The rule asks for one document, an honest map of where ePHI lives and what threatens it, and treats everything else in the Security Rule as flowing from it. OCR made the point structural in 2024 by building an entire enforcement initiative around this single provision. Doing the analysis well is genuinely cheaper than any alternative, including doing it badly.
| Requirement | 45 CFR 164.308(a)(1)(ii)(A) |
|---|---|
| Scope | All ePHI, enterprise-wide, asset-based |
| Not sufficient | Gap assessments, pen tests, questionnaires alone |
| Feeds | Risk management plan, 164.308(a)(1)(ii)(B) |
| Cadence | Periodic + on material change (annual in practice) |
| Enforcement | OCR Risk Analysis Initiative (2024-) |
Doing it right
Inventory before you assess. The ePHI asset and data-flow inventory is the analysis’s skeleton; the compliance roadmap shows where it anchors the whole program.
Rate risks you intend to treat. Every high risk needs a line in the risk management plan with an owner and date, unremediated known risks are what turn penalties from thousands into millions.
Cover the vendor edge. Business associates and their subcontractors hold your ePHI too; align the analysis with your BAA inventory and cloud arrangements.
Version and retain. Signed, dated, six years, with a change log that shows the analysis moved when the environment did; OCR’s enforcement trends show the document’s absence is the finding.
Web-facing systems belong in scope, tracker-based PHI leakage from hospital websites is an OCR-flagged risk: check your public pages with a free scan.