When people think about HIPAA enforcement, they think about the fines. The Office for Civil Rights imposed over $14 million in penalties last year, and the headlines focus on the dollar amounts. Those numbers are real, but they're not the whole story of what a failed audit actually costs a small practice.
Here's what the process actually looks like, from first contact to resolution.
How audits typically begin
Most small practice HIPAA audits don't start with a random selection. They start with a complaint. A patient files a complaint with the HHS Office for Civil Rights (OCR). An employee reports a concern. A breach notification triggers an investigation. A state health department refers a case.
When OCR receives a complaint, they review it to determine whether it's within their jurisdiction and whether it warrants investigation. If they open an investigation, you'll receive a written notification with a specific list of documentation they want to see. You typically have 30 days to respond.
The documentation request is where most practices discover their gaps. OCR will ask for your risk analysis, your written policies, your training records, your BAAs, and your breach response logs. If you haven't kept these, you're building them from scratch under a 30-day deadline.
What OCR looks for
The most common findings in small practice HIPAA investigations are:
- Missing or outdated risk analysis (required under the Security Rule)
- No written policies and procedures covering the Security Rule requirements
- Missing Business Associate Agreements with vendors who handle PHI
- Lack of access controls (shared logins, departed employees still with access)
- Unencrypted devices containing PHI
- No workforce training documentation
- Failure to report breaches within the required timeframe
The resolution process
Most HIPAA investigations don't result in the maximum penalty. OCR operates on a tiered system based on culpability:
- No knowledge: You had reasonable safeguards but the violation still occurred. Lower penalties, often resolved through a corrective action plan.
- Reasonable cause: You knew or should have known about the risk but didn't act on it. Moderate penalties.
- Willful neglect, corrected: You clearly failed to address a known problem but fixed it after being notified. Higher penalties.
- Willful neglect, not corrected: You failed to address a known problem and haven't fixed it. Maximum penalties.
For small practices that had reasonable intentions but incomplete compliance, investigations often resolve through a Resolution Agreement. You agree to implement specific corrective actions, submit to monitoring for one to three years, and sometimes pay a civil monetary penalty. The monitoring period is the part practices consistently underestimate.
The monitoring period changes everything. Under a Resolution Agreement, OCR receives regular reports on your compliance activities. Any new violation during the monitoring period is treated with heightened scrutiny. You're not just fixing the original problem; you're operating under a microscope for years.
The real cost beyond the fine
Practices that have been through HIPAA investigations consistently report that the fine is not the most painful part. The harder costs are:
- Legal fees: You'll almost certainly need legal representation during an investigation. Compliance attorneys who handle OCR matters typically charge $300 to $600 per hour.
- Staff time: Responding to an OCR investigation is a significant operational burden. Gathering documentation, drafting responses, implementing corrective actions, and maintaining monitoring reports takes real time away from patient care.
- Reputational impact: OCR publishes resolution agreements on their website. They're publicly searchable. Patients, referral sources, and payers can find them.
- Insurance implications: A HIPAA enforcement action may affect your cyber insurance renewals and your professional liability coverage.
The most effective response to a potential HIPAA audit is preparation that happens before one starts. A risk analysis, documented policies, signed BAAs, and training records don't prevent investigations from happening. They determine how those investigations resolve.
Find out where your audit gaps are before an auditor does.
The free Cyber Health Score takes 5 minutes and tells you which areas need attention most.
Get your free Cyber Health Score