
Brittany Brown
Manager, Healthcare Advisory, Coalfire
Healthcare


On April 23, 2026, the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) announced four settlements with HIPAA-regulated entities after separate ransomware investigations. In total, the incidents affected more than 427,000 individuals and resulted in $1,165,000 in settlements.
Across all four cases, OCR’s message was consistent: the organizations “failed to conduct an accurate and thorough risk analysis to determine the potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI.”
That’s why the HIPAA Security Rule Notice of Proposed Rulemaking (NPRM) is worth a close read: it doesn’t just reiterate the requirement of a risk analysis; it gets specific about what an accurate and thorough risk analysis should look like. Here is what HHS expects an accurate and thorough risk analysis to include:
And of course, what is a blog without mentioning AI. If you’re using AI tools that touch ePHI or influence decisions about ePHI, include them in your inventory, data-flow mapping, and threat modeling.
OCR’s April 2026 settlements are a reminder to ensure your organization is conducting an accurate, thorough, and timely risk analysis. Now is the time to refresh it, document it, and tie it directly to a holistic risk management program.