What OCR actually does: the settlements, read honestly
A curated set of real HIPAA enforcement actions, chosen for what they tell a small clinic: who gets investigated, what OCR finds, what it costs, and what would have prevented it.
Last verified: 2026-07-12
Enforcement pages usually exist to frighten people, and the numbers do most of the work. This one is built differently. Every action below was chosen because it tells a small clinic something specific and checkable, and each entry ends with the thing that would have prevented it.
Read them for the pattern rather than the money. The pattern is astonishingly consistent, and it is the most useful thing OCR has ever published about itself.
The one that is about you
Deer Oaks, a behavioral health provider. $225,000, July 7, 2025. Two-year corrective action plan.
OCR opened after a complaint that discharge summaries had been exposed online, and a separate cyberattack led to data being taken; notifications went to more than 171,000 individuals. OCR’s finding: the organization failed to conduct an accurate and thorough risk analysis of the risks to its ePHI.
Why this one matters more than the big numbers. Every clinic owner in behavioral health believes enforcement happens to hospitals and insurers. This is a behavioral health provider, penalized on the first requirement in the Security Rule, and the corrective action plan runs for two years after the check clears.
What would have prevented it: the risk analysis. Not a better firewall. The document that OCR asks for first.
The one that kills “we are too small”
MMG Fusion, a software company acting as a business associate. $10,000, March 5, 2026. Three-year corrective action plan.
An unauthorized actor got into the system in December 2020; PHI ended up on the dark web. OCR’s investigation began in 2023 after a complaint about an unreported security incident. In announcing the settlement, OCR said explicitly that it had considered the entity’s financial condition.
Read that carefully, because it is the whole argument. OCR did not decline to act because the organization was small. It acted, and set the number to what the organization could bear, and then attached three years of monitoring. OCR scales the penalty to the organization. It does not skip the organization.
What would have prevented it: timely breach notification, and again, a risk analysis.
“OCR scales the penalty to the organization. It does not skip the organization”
The four at once
Four ransomware settlements announced together on April 23, 2026. $1,165,000 total, more than 427,000 individuals affected. Two years of monitoring each.
Four separate organizations, four separate ransomware events, and one identical finding in all four: failure to conduct an accurate and thorough risk analysis before the breach.
What this reveals about how OCR works. The ransomware is how OCR arrives. The risk analysis is what OCR writes up. The attackers are not the subject of the enforcement action; the pre-incident governance is. OCR is, in effect, asking a single question after every breach: should this organization have been in a better position to prevent or contain this, and can it show that it tried?
What would have prevented it: not perfect security, which nobody has. A documented, current assessment of the risks, and evidence of acting on it. Several of those organizations may have had good intentions. None of them could show the work.
The pattern, stated plainly
Across the actions above and the broader run of OCR’s Risk Analysis Initiative since late 2024, the shape does not vary:
OCR arrives after an incident. A breach report, a complaint, a news story. Almost nobody is investigated at random.
OCR asks for the risk analysis first, and its absence or staleness becomes the core finding. It is the most cited deficiency in Security Rule enforcement, and it is the requirement that sits first in the rule (45 CFR 164.308(a)(1)(ii)(A)).
The number is scaled to the organization, from ten thousand dollars to millions, informed by the statutory factors (45 CFR 160.404 and 160.408), including financial condition and size.
The corrective action plan is the real cost. Two to three years of federal monitoring, reporting, and an OCR-approved remediation program. You do not pay and move on. You pay and then report, for years, while running a clinic.
And OCR is moving from analysis to management. It has said the initiative is expanding to ask not only whether you identified your risks but whether you closed them. A perfect analysis with an untouched findings list is the next profile in the crosshairs.
What this means for a clinic with thirty staff
Three honest conclusions.
You will not be investigated at random, and that is not comfort. You will be investigated after something goes wrong, and something goes wrong at every clinic eventually: a lost tablet, a misdirected fax, a phished credential, a vendor breach. The question is never whether the incident happens. It is what OCR finds when it looks at what you had in place before it.
The finding is almost always the same, and it is the cheapest one to fix. Not encryption, not a firewall, not an expensive tool. The document that describes, honestly, where your ePHI lives and what could go wrong with it. It is the first thing they ask for, and it is the thing most small clinics have never actually done.
Corrective action plans are what should scare you, not fines. A $10,000 settlement with three years of monitoring is not a small punishment for a small business. It is three years of a clinic’s leadership answering to a federal agency, on deadlines, while trying to see clients.
How this page is maintained
Curated, not automated. New actions are added when they teach a small clinic something it did not already know, and each one carries its primary HHS source. A page that simply lists every settlement would be a feed, and a feed goes stale and reads as neglect. This page is meant to be read once and understood, not scrolled.
Every figure and finding here is taken from OCR’s own announcements, linked in the sources. If a number here disagrees with a number you read elsewhere, check ours against the HHS link, and then check theirs.
The short version
- A behavioral health provider settled for $225,000 in July 2025 on the same finding as everyone else: no accurate and thorough risk analysis.
- OCR settles with small entities too, at small numbers: a software vendor paid $10,000 in March 2026, with OCR explicitly noting it considered the entity's financial condition.
- The breach is how OCR arrives. The risk analysis is what OCR writes up.
- The money is rarely the real cost. Almost every settlement carries a corrective action plan with two to three years of federal monitoring.
- Nearly every action on this page would have been prevented by work that costs an afternoon: a real risk analysis, encryption, and a BAA.
This article is educational information about the HIPAA regulations, not legal advice. It describes what the rules say; it does not tell you what to do about your specific situation, and reading it does not create an attorney-client or consultant-client relationship. Regulations change, and enforcement positions change with them. For advice on your clinic, talk to a qualified professional.
Sources
- HHS Office for Civil Rights settles HIPAA Privacy and Security Rule investigation with a behavioral health provider (Deer Oaks)HHS press release, July 7, 2025https://www.hhs.gov/press-room/ocr-hipaa-racap-deer-oaks.html
- HHS Office for Civil Rights settles four HIPAA Security Rule ransomware investigationsHHS press release, April 23, 2026https://www.hhs.gov/press-room/ocr-settles-four-ransomware-investigations.html
- HHS Office for Civil Rights settles HIPAA investigation of MMG Fusion, LLCHHS press release, March 5, 2026https://www.hhs.gov/press-room/ocr-mmg-fusion-hipaa-agreement.html
- HHS Office for Civil Rights, resolution agreements and civil money penaltiesHHS.govhttps://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/agreements/index.html
- Administrative safeguards, including risk analysis and risk management45 CFR 164.308https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.308
- Amount of a civil money penalty45 CFR 160.404https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-160/subpart-D/section-160.404
The finding they all share is the one you can fix.
Every action on this page traces to a risk analysis that did not exist or did not describe the organization. WiseUpHIPAA computes yours from what is actually true about your clinic, and shows you the gaps while they are still findings.