Walk into most medical or dental practices in Central Florida and ask to see their HIPAA compliance, and someone will bring you a binder. It has policies in it, usually written by a consultant several years ago. There is a training certificate from a video the staff watched last January. Somewhere in a shared drive there is a risk assessment spreadsheet that was filled out once, probably when the practice signed up for a new EHR. The office manager is confident it is all handled.
We have been doing this work for more than 15 years, and I want to be direct about something: that binder is not a compliance program. It is a collection of parts. The parts are not worthless, but they were built at different times by different people, they do not talk to each other, and nobody is responsible for keeping any of them current. When the Office for Civil Rights (OCR) shows up after a breach report or a patient complaint, it does not grade you on the parts. It grades you on whether the parts were connected into something that actually worked.
This post is about what a complete HIPAA compliance program looks like, why the gaps between the pieces are where practices get hurt, and what the enforcement record from the last year tells us about how OCR is thinking. I will also be honest about what a compliance program cannot do for you, because some of the marketing in this space oversells it.
What “complete” actually means
HIPAA has three main rules that matter to a practice: the Privacy Rule, the Security Rule, and the Breach Notification Rule. Between them, they require a set of ongoing activities, not a one-time project. A complete program covers all of them and, more importantly, keeps them tied together with documentation that proves they happened.
In practical terms, a complete program has six working parts:
| Component | What it has to do in practice |
|---|---|
| Workforce training | Every workforce member with access to patient information is trained on your actual policies, not a generic video. Completions and attestations are recorded, and new hires are trained before they touch records. |
| Policies and procedures | Written policies covering privacy, security, and breach response, tailored to how your practice really operates. Each policy has a version history and a record of which employees reviewed it and when. |
| Security risk analysis and risk management | A documented assessment of where electronic patient information lives, what threatens it, and how likely and severe each threat is. Then a written plan that closes the gaps, with owners and dates. Both get updated when something changes. |
| Business associate management | A current list of every vendor that creates, receives, stores, or transmits patient information on your behalf, with a signed business associate agreement for each and evidence you looked at their security. |
| Incident reporting and breach response | A way for staff to report something suspicious, a documented process for investigating it, and a decision record showing how you determined whether it was a reportable breach and what notifications went out. |
| Ongoing regulatory tracking | Someone, or something, watching for changes to the rules, penalty amounts, and OCR guidance, and pushing those changes into the training and policies above. |
Notice that every one of these rows ends with the same idea: a record. HIPAA compliance is fundamentally about being able to demonstrate what you did, when you did it, and who was responsible. A program that produces the right behavior but no documentation will fare almost as badly in an investigation as one that never did the work.
The gaps between the pieces are where enforcement happens
Here is the pattern I see in nearly every OCR enforcement action against a small provider. The practice was not ignoring HIPAA. It had training. It had policies. It usually had some kind of assessment. What it did not have was the connective tissue: the risk analysis never turned into a risk management plan, the policies were never updated after the assessment, or the training never covered what the policies actually said.
Consider a case OCR announced in February 2026. Top of the World Ranch Treatment Center, a substance use disorder provider in Illinois, reported a breach after a phishing attack gave an outside party access to a staff member’s email account. The affected patient count was 1,980. That is a small practice by any measure.
OCR’s finding was not that the practice got phished. Phishing happens to well-run organizations every day. The finding was that the practice had failed to conduct an accurate and thorough risk analysis of the risks to its electronic patient information. The settlement was $103,000 plus a corrective action plan that OCR will monitor for two years. Under that plan, the practice must complete a real risk analysis, build a risk management plan from it, rewrite its policies, and train staff on them. OCR ordered them to build the program they should have had before the incident.
The point that matters for your practice. The email compromise was the trigger for the investigation. The penalty was for the missing risk analysis. If that practice had been able to hand OCR a documented risk analysis, a risk management plan that showed email security was on the list, and training records showing staff had been taught about phishing, the outcome would very likely have been different. The breach still would have happened. The enforcement action might not have.
This is not an isolated case. OCR has been running what it calls a Risk Analysis Initiative since 2024, and it has stated publicly that it is expanding that initiative in 2026 to look at risk management as well: not just whether you did the assessment, but whether you acted on it. By April 2026, OCR had completed 13 investigations under that initiative and 19 investigations of ransomware breaches, and the central finding in nearly all of them was the same missing or inadequate risk analysis.
Enforcement is not limited to breaches, either. In August 2026, OCR settled with Azul Vision, a California optometry and ophthalmology provider, for $50,000 plus a two-year corrective action plan. There was no hack. A patient asked for her records in January 2023 and did not get them until January 2025, after OCR had already opened an investigation. The Privacy Rule requires access within 30 days, with one possible 30-day extension. That case was OCR’s 55th enforcement action in its Right of Access Initiative. A records request that falls through the cracks is a process failure, and process failures are exactly what a fragmented compliance approach produces.
What the penalties actually look like
I want to be careful here, because this is where a lot of compliance marketing gets inflated. You will see headlines quoting the maximum HIPAA penalty as though it is what a dental office should expect. It is not.
The current civil penalty amounts, adjusted for inflation and published in the Federal Register on January 28, 2026, are structured in four tiers based on culpability:
| Tier | Culpability | Per violation | Annual cap |
|---|---|---|---|
| Tier 1 | Did not know and could not reasonably have known | $145 to $73,011 | $2,190,294 |
| Tier 2 | Reasonable cause, not willful neglect | $1,461 to $73,011 | $2,190,294 |
| Tier 3 | Willful neglect, corrected within 30 days | $14,602 to $73,011 | $2,190,294 |
| Tier 4 | Willful neglect, not corrected | $73,011 to $2,190,294 | $2,190,294 |
Two honest qualifications. First, OCR announced in 2019 that it would exercise enforcement discretion and apply much lower annual caps to the first three tiers ($25,000, $100,000, and $250,000 respectively), reserving the full cap for uncorrected willful neglect. Second, the overwhelming majority of small-practice cases resolve as negotiated settlements, not formal penalties, and those settlements for small providers tend to land in the tens of thousands to low hundreds of thousands of dollars.
The number that gets less attention, and that I think matters more, is the corrective action plan. Two or three years of OCR monitoring means regular reporting to a federal agency, mandatory rebuilds of your policies and training, and an outside eye on every step. For a small practice, the administrative cost of living under a corrective action plan often exceeds the settlement check. That is before patient notification costs, legal fees, and the conversation with your cyber insurance carrier.
Note where the tiers place the line. Willful neglect is the difference between a modest penalty and a serious one, and the way OCR determines willful neglect is by looking at your documentation. A practice that can show it identified a risk, planned to fix it, and was working the plan is in a fundamentally different position from a practice that never looked.
The day-to-day benefits nobody puts in the headline
Enforcement risk gets the attention, but most of the practice owners I work with feel the value of a complete program in much more ordinary ways.
- You know who is actually trained. Not who was assigned the video, but who completed it, when, and which version of the policies they attested to. When a new hire starts on Monday, there is a defined process rather than a reminder on a sticky note.
- You can answer the vendor question. Practices work with more outside parties than they realize: the billing company, the cloud backup vendor, the IT provider, the patient communication platform, the shredding service, the cleaning crew with after-hours access. A complete program keeps the list, the signed agreements, and the due diligence in one place. When one of those vendors has a breach, and eventually one will, you know immediately whether your patients are affected.
- Incidents get handled the same way every time. A staff member clicks something and then feels sick about it. Under a fragmented approach, that gets mentioned to the office manager, maybe, three days later. Under a complete program, there is a reporting path, a triage process, and a written breach risk assessment that shows your reasoning if the decision is ever questioned.
- Cyber insurance renewals get easier. Carriers now ask detailed questions about risk assessments, training, multifactor authentication, and vendor management. Practices that can answer with documents rather than guesses get better terms and fewer exclusions. (See How to Answer Cyber Insurance Renewal Questions Without Voiding Your Policy.)
- Referral partners and hospital systems ask too. Larger organizations you exchange records with are conducting their own due diligence on you as their business associate or partner.
There is also a benefit that only shows up when something goes wrong, and it is written into federal law.
Documented security practices can reduce penalties, but only if you can prove them
In January 2021, Congress amended the HITECH Act to require HHS to consider whether a regulated entity had “recognized security practices” in place for the previous 12 months when deciding penalties, audit scope, and settlement terms after a Security Rule investigation. Recognized security practices include the NIST Cybersecurity Framework and the Health Industry Cybersecurity Practices published under section 405(d) of the Cybersecurity Act of 2015.
OCR has been explicit that this is not a safe harbor. It does not make you immune from penalties, and it does not apply to Privacy Rule or Breach Notification Rule violations. What it does is give a practice that can demonstrate a documented, enterprise-wide security program a mitigating factor that can reduce both the financial penalty and the scope of what OCR asks for.
The operative word is demonstrate. OCR wants evidence that the practices were in place across the organization for a full year before the incident: policies, configuration records, training logs, assessment results, vendor audits. A practice that runs its security well but keeps no records cannot claim this. A practice with a complete compliance program produces that evidence as a byproduct of normal operation.
Where the rules are heading, and what we do not know yet
In January 2025, HHS published a proposed overhaul of the Security Rule, the first substantial update since 2013. (We walked through the proposal in detail in The Proposed HIPAA Security Rule: A Step-by-Step Guide for Medical and Dental Practices.) The proposal would make encryption of electronic patient information at rest and in transit mandatory, require multifactor authentication, require a written asset inventory and network map, require vulnerability scanning every six months and annual penetration testing, and impose a 72-hour restoration requirement for critical systems. It would also eliminate the “addressable” flexibility that currently lets smaller practices document why they chose not to implement certain controls.
I would be misleading you if I told you this is the law. It is not. The comment period closed in March 2025, and HHS’s own regulatory agenda now lists final action for July 2027, pushed back from an earlier spring 2026 target. (See The HIPAA Security Rule Update Slipped to 2027 for what to do with the extra time.) Industry groups have pushed hard against the cost burden on small providers, and the final rule could be narrowed, delayed again, or in theory withdrawn. Anyone selling you a product to “comply with the 2026 Security Rule” is selling you compliance with a proposal.
What I can tell you is that the direction is clear, and that most of what the proposal would require is already what OCR expects a reasonable practice to be doing under the current rule. The current Security Rule already requires the risk analysis. OCR’s own recommendations in the Top of the World Ranch settlement already include encrypting patient information, authenticating users, reviewing system activity logs, and training staff on their specific job duties. A practice with a complete program today will have very little distance to cover when the final rule arrives, whatever form it takes. A practice with a binder will be starting from scratch on a 180-day clock.
What a compliance program will not do for you
This is the section the vendors leave out, and it is the part I think matters most.
A complete compliance program will not make you unbreachable. HIPAA compliance and cybersecurity overlap, but they are not the same thing. Compliance is about having identified your risks, having reasonable safeguards, and being able to prove it. Security is about the safeguards actually stopping attacks: multifactor authentication on every account, endpoint detection on every device, tested backups, patched systems, and email filtering that catches most of what gets through. You can be fully compliant and still get hit. You can also run good security and be badly out of compliance because nobody wrote anything down. You need both: the risk analysis tells you what security to prioritize, and the security controls become the evidence in the compliance record.
A software platform will not run itself. The compliance platforms on the market do a lot of useful work: they track training, manage policy attestations, structure the risk assessment, hold vendor documents, and push regulatory updates so you do not have to read the Federal Register. That is real value. But someone in your practice has to own it. Someone has to answer the risk assessment questions truthfully, follow up on the remediation tasks, chase the vendor who never returned the agreement, and log the incident when a staff member reports it. The platform organizes the work. It does not do the work.
And I should say plainly that Harmony MSP has a commercial interest here. We help practices build and run these programs, and we bundle compliance into the managed IT service rather than selling it as a separate line item, because in our experience the two fall apart when they are managed by different people. That is our business model, and it serves us as well as it serves you. It does not change the facts above, but you should know where I sit when I make the argument.
Five questions to ask about your own practice
If you want to know whether you have a program or a collection of parts, these five questions will tell you. Ask your office manager, or ask your IT provider, and pay attention to how long it takes to get an answer.
- When was our last security risk analysis, and where is the risk management plan that came out of it? What is the status of each item on that plan?
- Which version of our privacy and security policies has each employee attested to, and when? Do the policies describe how we actually operate today?
- Can we produce a list of every vendor that touches patient information, with a signed business associate agreement for each, in under an hour?
- If a staff member reported a suspicious email right now, what would happen next, and who would write down the decision about whether it is a reportable breach?
- Who is responsible for noticing when HHS changes a rule or a penalty amount, and how does that change reach our training and policies?
If any of those produced a long pause, the gap is real, and it is the same gap OCR finds in most of its investigations. Closing it does not require a large practice or a large budget. It requires deciding that HIPAA is an ongoing program rather than an annual chore, and putting a structure around it that keeps the pieces connected.
If you want a second opinion
If you would like a second opinion on where your practice stands, Harmony MSP offers a no-obligation HIPAA program review for practices in the Orlando and Central Florida area. We will look at what you have, tell you plainly what is missing, and give you a written summary you can act on whether or not you ever work with us. Call us at (407) 720-6540 and ask for a compliance review.
Sources
- HHS Office for Civil Rights, “HHS’ Office for Civil Rights Settles HIPAA Security Rule Investigation with Top of the World Ranch Treatment Center,” February 19, 2026
- HHS Office for Civil Rights, “HHS’ Office for Civil Rights Settles HIPAA Right of Access Investigation with Azul Vision, Inc.,” August 27, 2026
- HHS Office for Civil Rights, “HHS’ Office for Civil Rights Settles Four HIPAA Security Rule Ransomware Investigations,” April 23, 2026
- HHS, Annual Civil Monetary Penalties Inflation Adjustment, Federal Register, January 28, 2026
- HHS, Notification of Enforcement Discretion Regarding HIPAA Civil Money Penalties, Federal Register, April 30, 2019
- HHS Office for Civil Rights, Security Rule Guidance Material, including the Recognized Security Practices video presentation (Public Law 116-321)
- HHS Office for Civil Rights, Guidance on Risk Analysis Requirements under the HIPAA Security Rule
- HHS Office for Civil Rights, HIPAA Security Rule Notice of Proposed Rulemaking, 90 FR 800, January 6, 2025
- HHS Office for Civil Rights and ASTP/ONC, Security Risk Assessment Tool for small and medium-sized practices
- 45 CFR 164.308(a)(1)(ii)(A) (risk analysis), 164.308(a)(5) (security awareness and training), 164.530(b) (Privacy Rule training), 164.524 (right of access)
Note on sources: the final-rule timing for the Security Rule update is taken from the OMB Unified Agenda entry (RIN 0945-AA22) as reported in July 2026 and is subject to change. Penalty tier figures are from the Federal Register notice above. OCR’s stated expansion of the Risk Analysis Initiative to include risk management is from public statements by the OCR Director and has not been formalized in rulemaking.



