In April 2026, the Department of Health and Human Services Office for Civil Rights resolved four separate ransomware investigations for a combined $1,165,000. The breaches affected more than 427,000 individuals. Each entity also agreed to a corrective action plan under two years of OCR monitoring. The resolutions contain no admission of liability, but the focus of all four is the same and it is worth noting: pre-breach compliance, and risk analysis in particular, rather than the attacks themselves.

That pattern is familiar. Risk analysis, the requirement at 45 CFR 164.308(a)(1)(ii)(A), has been the most frequently cited Security Rule violation in financial settlements for years. What practitioners tracking OCR enforcement activity through 2026 are now reporting is a shift in the second half of that inquiry: not only whether an organization identified its risks, but whether it did anything about them.

A note on what this is and is not. This is practitioner reporting on enforcement posture, drawn from attorneys and consultants who track OCR settlements and public statements. It is not a published OCR policy statement, and OCR has not issued a rule change. Treat it as a read on where enforcement attention is heading, not as a citation to new law.

The requirement was always two parts

45 CFR 164.308(a)(1)(ii)(A) requires a risk analysis: an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information.

45 CFR 164.308(a)(1)(ii)(B), sitting in the same paragraph, requires risk management: security measures sufficient to reduce those risks and vulnerabilities to a reasonable and appropriate level.

The second requirement has never been optional. It has sat next to the first one since the Security Rule took effect. For most of the enforcement initiative's history, OCR's attention concentrated on subsection (A): did the entity look. What practitioner reporting now describes is enforcement attention moving to subsection (B): did the entity act, and can it prove it. Nothing about the rule changed. What changed is which half of it gets checked.

Most organizations have half the record

Ask a small medical practice or a defense subcontractor for their risk analysis and most can produce something. A spreadsheet, a consultant's report, a document with a date on it and a list of findings. Missing encryption on a laptop. No formal access review. A vendor without a signed agreement.

Ask the same organization to show what happened to each finding after the document was filed, and the record usually stops. There is a list, and there is silence after the list. Nobody can say who was assigned the encryption gap, when it closed, or what evidence exists that it closed at all. The risk analysis proves the organization knew about a weakness. It does not prove the organization fixed it.

Under an older enforcement posture, that gap was survivable. A dated risk analysis read as reasonable diligence even when follow-through was thin. Under the posture practitioners are now describing, the same document works against the organization. A risk analysis with no closure trail is no longer a record of due diligence. It is a record of notice: proof the organization knew about the gap that later became the breach, and did not close it.

The document that becomes the exhibit

This is the part worth sitting with. The risk analysis was supposed to be the artifact that showed good faith. Under a risk management enforcement lens, an unclosed finding turns that same document into the opposite: an exhibit showing the organization had notice and did not act. The April 2026 resolutions point the same direction. What drew the attention was not the ransomware. It was the state of compliance before the ransomware arrived.

The fix is four columns

The practical response does not require a new framework or a new tool. It requires a change to the risk analysis document itself. Beside every finding, add four columns: who owns the finding, what action was taken, on what date, and which artifact proves the action closed it.

Owner turns a list item into an assignment. A finding with no name attached to it is nobody's job, and nobody's job does not get done.

Action taken and date turn the finding into a timeline. A regulator, or an assessor, can see not only that a gap was known, but when the organization responded to it.

The artifact is the column that matters most, because it is the one most organizations cannot fill in today. A closed finding needs proof: a screenshot of an enabled setting, a signed vendor agreement, an invoice for encryption software, a change ticket. Without the artifact, closed is a claim. With it, closed is a record.

Four columns convert a document that lists what an organization knew into a record of what an organization did. That is the distinction the widened enforcement posture is reported to be drawing, and it is a distinction every organization holding electronic protected health information can address without waiting for OCR to publish anything further.

Where to start

Pull the most recent risk analysis. For every open finding, write in the owner, the planned action, and the target date, even where the artifact does not exist yet. That alone turns a static list into a working plan, and a working plan with a visible update cadence is a materially different piece of evidence than a document that has not moved since the day it was filed.

Adams Cloud & Cybersecurity works with small healthcare organizations to build this record alongside the risk analysis itself, so the document a practice already has stops being a liability and starts being proof of the work that was actually done.

Sources

Is your risk analysis a record of what you did, or just what you found?

Adams Cloud works with small healthcare organizations to build the closure trail alongside the risk analysis itself, so the document you already have becomes evidence of remediation rather than notice of a gap.

Book a free consultation