A $4.75 Million Fine Started with One Missing Risk Analysis

In 2023, Banner Health agreed to a $1.25 million settlement with OCR after a breach exposed the ePHI of nearly 3 million people. The root cause? Failures in risk analysis and risk management — the exact foundations of HIPAA security compliance. And Banner wasn't a small practice cutting corners. It was a massive health system with dedicated IT teams.

I've seen this pattern repeat dozens of times across organizations of every size. They invest in firewalls and encryption but skip the unglamorous work of documenting risks, training their workforce, and actually following through on policies. The result is a compliance posture that looks sturdy on the outside but collapses the moment OCR comes knocking.

This post breaks down the specific areas where organizations fail at HIPAA security compliance — and what you can do differently, starting this week.

What HIPAA Security Compliance Actually Requires

Let's get specific. The HIPAA Security Rule isn't a vague suggestion to "keep data safe." It's a set of administrative, physical, and technical safeguards designed to protect electronic protected health information (ePHI). Every covered entity and business associate must implement them.

The rule requires you to:

  • Conduct a thorough, documented risk analysis
  • Implement risk management plans that address identified vulnerabilities
  • Deploy access controls, audit controls, and transmission security
  • Train your entire workforce on security policies and procedures
  • Maintain documentation for six years

Most organizations check one or two of those boxes. Almost nobody checks all five consistently. That gap is where enforcement actions live.

The Risk Analysis Problem Nobody Wants to Talk About

Here's what I tell every client on day one: if you don't have a current, comprehensive risk analysis, nothing else you do matters. OCR has made this painfully clear through settlement after settlement.

In its resolution agreement with Premera Blue Cross, OCR cited the lack of an adequate risk analysis as a primary failure — contributing to a breach affecting over 10.4 million individuals. The settlement cost Premera $6.85 million.

A risk analysis isn't a one-time checklist. It's a living document that evolves as your technology stack changes, as your workforce shifts to remote environments, and as new threats emerge. If yours is sitting in a drawer from 2022, you're exposed.

What a Real Risk Analysis Looks Like

A compliant risk analysis identifies every system that creates, receives, stores, or transmits ePHI. It evaluates threats and vulnerabilities specific to each system. It estimates the likelihood and impact of each threat. And it documents what controls are in place — and what gaps remain.

That last part is critical. OCR doesn't penalize you for having gaps. It penalizes you for not knowing about them or not addressing them.

Workforce Training: The $1.9 Million Lesson Most Organizations Skip

In 2020, CHSPSC LLC paid $2.3 million to settle allegations stemming from a breach that affected over 6 million individuals. Among the findings: the organization failed to implement adequate information system activity review and workforce training.

Your staff doesn't need to become cybersecurity experts. But they do need to understand how to handle ePHI, how to recognize phishing attacks, and what to do if they suspect a breach. The Security Rule requires training for all workforce members — not just clinical staff, not just IT.

This is especially urgent now that so many healthcare workers operate remotely. A laptop on a home Wi-Fi network is a fundamentally different risk than a workstation inside your firewall. If your training hasn't caught up with that reality, your organization is carrying unnecessary risk. Our HIPAA training for remote healthcare workers was built specifically to close that gap.

Remote Work Broke Your Security Perimeter — Have You Fixed It?

I've audited organizations where half the workforce went remote in 2020 and nobody updated the risk analysis until 2024. Four years of unmanaged risk. Four years of staff accessing ePHI on personal devices, over unsecured networks, sometimes from coffee shops.

HIPAA security compliance in 2026 demands that you account for every environment where ePHI is accessed. That includes home offices. That includes personal smartphones used for two-factor authentication. That includes the cloud-based EHR your staff logs into from their kitchen table.

If you haven't addressed remote work in your policies and training, start with our Working from Home & PHI course. It covers the specific technical and behavioral safeguards remote workers need to follow.

The AI Wildcard

And then there's artificial intelligence. Clinicians and administrative staff are increasingly using AI tools to draft notes, summarize records, and automate tasks. Many of those tools process data on external servers. If PHI enters a prompt, you may have just created an unauthorized disclosure.

This is a HIPAA security compliance issue that barely existed two years ago. Now it's one of the fastest-growing risk vectors I encounter. HHS hasn't issued AI-specific regulations yet, but the existing Security Rule already covers it: if a tool touches ePHI, it needs to be in your risk analysis, covered by a business associate agreement, and addressed in workforce training. Our Using AI Tools & PHI training module walks your team through exactly how to handle this.

What Happens When HIPAA Security Compliance Fails

OCR's enforcement page tells the story better than I can. The resolution agreements archive lists dozens of settlements, and the same failures appear again and again:

  • No risk analysis or an incomplete one
  • No risk management plan addressing known vulnerabilities
  • Lack of audit controls or failure to review audit logs
  • Insufficient access controls — too many people with too much access
  • No encryption on portable devices
  • Failure to train workforce members

Penalties range from tens of thousands to millions of dollars. In 2023, OCR settled with Lafourte Medical Group for $480,000 after a phishing attack exposed ePHI — and the investigation revealed a missing risk analysis and inadequate security policies.

These aren't exotic, sophisticated failures. They're basic blocking and tackling that organizations skip because compliance feels expensive and time-consuming. Until the breach happens. Then it's orders of magnitude more expensive.

How Do You Achieve HIPAA Security Compliance?

Here's the direct answer. You achieve HIPAA security compliance by systematically implementing the administrative, physical, and technical safeguards required by the HIPAA Security Rule (45 CFR Part 164, Subpart C). Start with a comprehensive risk analysis. Build a risk management plan. Implement access controls, encryption, and audit logging. Train every workforce member. Document everything. Review and update annually — or whenever your environment changes.

That's the framework. The execution is where most organizations struggle.

Five Things You Can Do This Month

You don't need to overhaul everything at once. Here's where to start:

1. Verify Your Risk Analysis Is Current

If it's older than 12 months or doesn't reflect your current systems and workforce model, it's outdated. Update it or commission a new one.

2. Audit Access Controls

Pull a list of everyone with access to ePHI systems. Compare it to current job roles. Revoke access for anyone who doesn't need it. This takes a few hours and eliminates one of OCR's most common findings.

3. Check Encryption on Every Device

Every laptop, tablet, and phone that can access ePHI should have full-disk encryption enabled. No exceptions. Unencrypted stolen devices trigger breach notification requirements under the HHS Breach Notification Rule.

4. Train Your Staff — Especially Remote Workers

Annual training is the minimum. If you've added AI tools, shifted to hybrid work, or changed EHR systems, your workforce needs updated training now. Browse our full course catalog for role-specific options.

5. Document Your Policies and Incidents

If it's not written down, it didn't happen — at least as far as OCR is concerned. Make sure every policy, training session, risk assessment, and incident response is documented and retained for at least six years.

Compliance Isn't a Destination — It's a Cycle

I've worked with organizations that aced their first compliance review and then let everything decay for three years. By the time they faced an incident, their documentation was stale, their training records were incomplete, and their risk analysis didn't mention half the systems in active use.

HIPAA security compliance is an ongoing cycle of assessment, implementation, training, and review. The organizations that stay out of trouble treat it like a core business function — not a project with an end date.

Your threat landscape changes every quarter. Your workforce turns over. Your technology evolves. Your compliance program has to keep pace, or it's just paperwork.

Start where you are. Fix what's broken. Train your people. And do it again next year. That's the entire secret.