Breach analysis · Patient Protect
Risk Analysis and Contingency Planning: The Two HIPAA Controls OCR Finds Missing After Every Ransomware Settlement
OCR's ransomware enforcement pattern reveals a predictable compliance gap—here's how to close it before regulators come looking.
The control gap
Ransomware settlements with HHS OCR follow a consistent pattern: investigators do not treat an attack as an external misfortune that absolves the covered entity. They treat it as evidence that risk analysis and contingency planning failures existed long before the threat actor arrived. OCR's enforcement record, spanning guidance issued in 2016 through enforcement actions continuing today, shows regulators examining the full compliance record — the months or years of documented activity, or inactivity — that preceded the incident. Recent reporting in HIPAA Pulse on the OSF Healthcare System settlement illustrates the pattern precisely: a 2021 ransomware intrusion by the Xing Team triggered an OCR investigation that scrutinized not just the attack itself but whether foundational Security Rule requirements were met upstream. First reported in HIPAA Pulse →(https://hipaapulse.com/hhs-ocr-settles-ransomware-investigation-of-osf-healthcare-system-and-affiliated-covered-entities-a852a8c7)
For independent and small-group practices, the implication is direct. Scale changes the financial penalty — IBM Security's 2024 Cost of a Data Breach report places the healthcare industry average above $9.8 million — but it does not change the compliance obligation. The same framework that applies to a multi-hospital system applies to a five-physician group.
The HIPAA Security Rule provision in play
Two provisions are consistently implicated in ransomware enforcement:
- §164.308(a)(1) — Risk Analysis and Risk Management: requires a current, documented assessment of threats and vulnerabilities to ePHI, updated after operational changes and at regular intervals.
- §164.308(a)(7) — Contingency Plan: requires data backup plans, disaster recovery plans, an emergency mode operation plan, and testing and revision procedures — specifically designed to maintain access to ePHI when primary systems are unavailable.
OCR's corrective action plans in ransomware settlements routinely mandate remediation of both provisions, along with breach notification workflow gaps under §164.404 (60-day notification clock, running from the date of discovery, not containment).
How Patient Protect addresses this
- Security Risk Assessment (SRA): Patient Protect's guided SRA produces a current, documented risk analysis tied to your specific environment — the primary artifact OCR requests at the outset of any ransomware investigation.
- Autonomous Compliance Engine: Continuously recalculates your compliance posture as your environment changes, so risk analysis currency is maintained operationally, not just at annual review.
- Policy Generation: Produces written incident response, breach notification, and contingency planning documentation — the procedural record OCR examines when evaluating whether notification delays reflect systemic non-compliance.
- Workforce Management and Office Training (80+ modules): Documents staff training completion, a mandatory corrective action plan requirement in nearly every OCR ransomware settlement.
- Compliance Scoreboard: Provides an at-a-glance compliance-state view so administrators can identify and close gaps before an incident — not after OCR opens an inquiry.
Practical next steps
- Run or update your SRA this week. An incomplete or stale risk analysis is the finding OCR leads with. A current document changes your regulatory posture immediately.
- Document your breach-determination workflow. Assign named roles, map the 60-day notification clock to calendar milestones, and identify where delays are most likely to occur.
- Verify backup isolation. Confirm that at least one backup copy is offline or immutable and that recovery procedures have been tested within the past 12 months.
- Audit privileged access. Restrict administrative credentials to personnel who require them and confirm logging is active for all privileged sessions.
- Check BAA currency for any vendor with network access. Remote access tools and cloud integrations are common ransomware entry points; a current, enforceable BAA is required and the vendor's controls should appear in your risk analysis.
Try Patient Protect
- Start a free trial at hipaa-port.com → https://hipaa-port.com
- Run a free Security Risk Assessment at patient-protect.com/risk-assessment → https://patient-protect.com/risk-assessment
This commercial companion is published by Patient Protect and may be co-written with editorial AI assistance, drawing on the source HIPAA Pulse article. First reported in HIPAA Pulse → https://hipaapulse.com/hhs-ocr-settles-ransomware-investigation-of-osf-healthcare-system-and-affiliated-covered-entities-a852a8c7
