Back to resources

When people think about HIPAA enforcement, they think about the fines. The Office for Civil Rights imposed over $14 million in penalties last year, and the headlines focus on the dollar amounts. Those numbers are real, but they're not the whole story of what a failed audit actually costs a small practice.

Here's what the process actually looks like, from first contact to resolution.

How audits typically begin

Most small practice HIPAA audits don't start with a random selection. They start with a complaint. A patient files a complaint with the HHS Office for Civil Rights (OCR). An employee reports a concern. A breach notification triggers an investigation. A state health department refers a case.

When OCR receives a complaint, they review it to determine whether it's within their jurisdiction and whether it warrants investigation. If they open an investigation, you'll receive a written notification with a specific list of documentation they want to see. You typically have 30 days to respond.

The documentation request is where most practices discover their gaps. OCR will ask for your risk analysis, your written policies, your training records, your BAAs, and your breach response logs. If you haven't kept these, you're building them from scratch under a 30-day deadline.

What OCR looks for

The most common findings in small practice HIPAA investigations are:

The resolution process

Most HIPAA investigations don't result in the maximum penalty. OCR operates on a tiered system based on culpability:

For small practices that had reasonable intentions but incomplete compliance, investigations often resolve through a Resolution Agreement. You agree to implement specific corrective actions, submit to monitoring for one to three years, and sometimes pay a civil monetary penalty. The monitoring period is the part practices consistently underestimate.

The monitoring period changes everything. Under a Resolution Agreement, OCR receives regular reports on your compliance activities. Any new violation during the monitoring period is treated with heightened scrutiny. You're not just fixing the original problem; you're operating under a microscope for years.

The real cost beyond the fine

Practices that have been through HIPAA investigations consistently report that the fine is not the most painful part. The harder costs are:


The most effective response to a potential HIPAA audit is preparation that happens before one starts. A risk analysis, documented policies, signed BAAs, and training records don't prevent investigations from happening. They determine how those investigations resolve.

Find out where your audit gaps are before an auditor does.

The free Cyber Health Score takes 5 minutes and tells you which areas need attention most.

Get your free Cyber Health Score