OCR enforcement has become legible: the agency tells you what it will penalize, then penalizes exactly that. The Right of Access Initiative punishes slow record releases; the Risk Analysis Initiative punishes the missing foundation document; ransomware investigations recite the same three failures every time. The tier system rewards the same behavior twice, entities that find and fix problems land in discretionary tiers, while conscious neglect mandates penalties, and settlement-with-CAP remains the near-universal outcome for entities that engage. The playbook writes itself: keep the risk analysis current, answer patients in 30 days, review the logs, and produce documents like you expected to be asked.
| Initiative | Target | Typical outcome |
|---|---|---|
| Right of Access (2019-) | 164.524 delays/denials | $3K-$240K + CAP |
| Risk Analysis (2024-) | Missing 164.308(a)(1) analysis | 5-7 figures + CAP |
| Ransomware/hacking reviews | Risk analysis, access controls, log review | Settlements to 8 figures |
| Tiers | Culpability 1-4, inflation-adjusted | Cap ≈ $2.1M/category/year |
Enforcement-proofing the program
Fix the two initiative targets first. A current risk analysis and a tracked 30-day access queue neutralize the two active programs.
Assume the document request. The roadmap’s artifacts, policies, BAAs, training logs, breach files, are the production set; organize them before the letter arrives.
Correct within 30 days. Documented correction moves willful neglect from mandatory-penalty tier 4 to tier 3; remediation speed is penalty math.
Mind the parallel regulators. State AGs, the FTC’s health rules, and class actions run on their own clocks after every breach.
OCR has flagged website tracking as a compliance issue in its own right: see what your pages send third parties with a free scan.