The Office for Civil Rights (OCR) closed 2025 with 21 settlements and civil monetary penalties, the second highest annual total on record. That volume did not come from random audits. It came from a small, predictable set of failure categories that repeat across nearly every case: unauthorized disclosure of protected health information, missing business associate agreements, incomplete risk analyses, and breach notifications sent too late.
This article breaks down those categories using OCR's own enforcement record and the requirements written into the Health Insurance Portability and Accountability Act (HIPAA) and the Health Information Technology for Economic and Clinical Health (HITECH) Act. The core point is straightforward: enforcement follows documented gaps in specific, well-known rules, not bad luck. Organizations that understand which failures OCR investigates most often can close those gaps before a complaint or breach report reaches a federal investigator.
What Does PHI Stand For, and Why Does It Drive Every Violation Category?
Protected health information (PHI) is any individually identifiable health information created, received, maintained, or transmitted by a covered entity or its business associates. This includes medical records, billing details, appointment data, and any identifier tied to a patient's health status or treatment. Nearly every HIPAA violation category traces back to a failure to protect, disclose, or account for PHI correctly, whether the failure involves an email sent to the wrong recipient, a server left unencrypted, or a vendor handling patient data without a signed agreement.
Common HIPAA Violation Categories OCR Investigates
HIPAA violation examples generally fall into five recurring categories, and OCR's recent settlements confirm the pattern. These settlements point to consistent enforcement priorities:
- Timely patient Right of Access;
- A prohibition on impermissible disclosures including those made via websites and social media;
- Foundational Security Rule obligations (especially accurate and thorough risk analysis and risk management);
- Timely breach notification;
- Workforce training and policy maintenance.
Impermissible Disclosure of PHI
Impermissible disclosure covers any sharing of PHI outside what the Privacy Rule permits, including posts on social media, embedded tracking tools on patient portals, or records handed to the wrong party. OCR treats these disclosures as a top enforcement priority alongside access delays and security failures.
Security Rule Risk Analysis Failures
A risk analysis failure occurs when a covered entity or business associate never conducts, or never updates, a documented assessment of threats to electronic protected health information (ePHI). Recent resolution agreements consistently address defects in basic Security Rule compliance, with a common finding that the organization failed to conduct a thorough risk analysis consistent with the HIPAA Security Rule. Risk analysis failures are the most commonly identified HIPAA Security Rule violation in OCR's investigations of data breaches and audits, and this single gap now drives more enforcement actions than any other issue.
Right of Access Violations
Patients have a right to obtain a copy of their own records within a defined window, and OCR pursues complaints when that window is missed by a wide margin. In one settlement, OCR resolved alleged Right of Access violations after determining a covered entity failed to provide an individual's PHI within 30 days despite multiple requests, with access ultimately provided more than a year after the initial request. Organizations are expected to track the 30-day deadline, with one possible 30-day extension, to avoid these complaints.
Missing Notice of Privacy Practices
The Notice of Privacy Practices (NPP) is the written statement every patient receives explaining how a provider may use and disclose PHI, along with the patient's rights and the provider's legal duties. Under 45 CFR 164.520, a healthcare provider with a direct treatment relationship must provide the Notice of Privacy Practices no later than the date of first service delivery, including service delivered electronically. A missing, outdated, or improperly distributed notice is a documentation gap that surfaces quickly during any OCR review.
Missing or Noncompliant Business Associate Agreements
A business associate agreement (BAA) is the contract required between a covered entity and any vendor that creates, receives, maintains, or transmits PHI on its behalf. In practical terms, a BAA is the legal document that extends HIPAA's privacy and security obligations to that vendor. A covered entity is required to enter into a contract or other written arrangement with a business associate that meets the requirements at 45 CFR 164.504(e), which spells out exactly what the agreement must contain. A BAA must establish the permitted and required uses and disclosures of PHI, prohibit the business associate from using or disclosing the information beyond what the contract or law permits, and require appropriate safeguards, including Security Rule requirements for electronic PHI. Working with a billing company, cloud host, IT vendor, or answering service without this agreement in place is one of the most common and most avoidable violations OCR identifies.
How Does the HITECH Act Shape Breach Notification Requirements?
HITECH is the 2009 law that added a mandatory breach notification framework to HIPAA and extended direct liability to business associates and their subcontractors. HITECH strengthened HIPAA by creating the federal breach notification rule, extending direct liability to business associates and their subcontractors, increasing enforcement and penalty tiers, and promoting adoption of security controls such as encryption. Before HITECH, business associates faced far less direct exposure for mishandling PHI. That changed permanently once the law took effect.
The notification timeline is fixed and applies regardless of organization size. Breach notification letters must be sent within 60 days of the discovery of a breach, unless a shorter timeframe exists under state law or a delay has been requested by law enforcement. For larger incidents, additional reporting applies. For breaches affecting 500 or more individuals, HHS must be notified within the same 60-day window. Breaches affecting fewer than 500 individuals are reported in an annual summary submitted within 60 days after the end of the calendar year. Media notice is also required within 60 days if 500 or more residents of a state or jurisdiction are affected. Missing any of these windows converts a security incident into a separate, documented compliance failure.
What Do the Penalties Actually Look Like?
Civil monetary penalties scale with culpability, from simple lack of knowledge to willful neglect that goes uncorrected. Penalties for HIPAA violations include civil monetary penalties ranging from $145 to $2,190,294 per violation, depending on the level of culpability. Most resolutions, however, pair a financial settlement with a multi-year corrective action plan (CAP) that mandates new policies, updated risk analyses, and ongoing monitoring. The financial number rarely tells the full story. CAP obligations often carry a heavier operational burden than the settlement itself.
Why Enforcement Trends Point Toward Prevention, Not Reaction
OCR's current enforcement posture centers on a narrow set of repeat failures rather than sweeping new rules. Risk analysis gaps, delayed access responses, missing BAAs, and late breach notices account for the large majority of recent resolution agreements. Closing those specific gaps, rather than waiting for a complaint or breach to force the issue, remains the more defensible position for any organization handling PHI.
Getting Ahead of HIPAA Enforcement Risk
Planet 9 is a Bay Area cybersecurity consulting firm specializing in HIPAA readiness for small and midsize businesses in healthcare, SaaS, and technology. Our vCISOs and compliance managers help organizations choose the right approach, configure GRC tools if needed, and get audit-ready without wasted time.




.png)
