Yesterday, February 19, 2026, the HHS Office for Civil Rights announced a $103,000 settlement with Top of the World Ranch Treatment Center, a substance use disorder treatment provider in Illinois. The facts are ordinary, and they explain better than any guidance document why a HIPAA risk analysis for a small practice matters. In early 2023, an attacker phished a workforce member, got into that person's email account, and had access to electronic protected health information for 1,980 patients. The center reported the breach in March 2023. OCR investigated and found what it has found in ten prior cases under its Risk Analysis Initiative: the organization had never conducted an accurate and thorough risk analysis of its electronic protected health information.
That is the eleventh settlement in the initiative, and the pattern is now impossible to miss. OCR is not fining organizations for being phished. It is fining them for not having done the one piece of work the Security Rule has required since 2005, and it is choosing small and mid-sized providers as often as large ones. A 1,980-patient breach is a small practice's breach. A $103,000 settlement plus a two-year corrective action plan is a small practice's penalty.
So this article does two things. It tells you what the settlement requires, because the corrective action plan is a list of what OCR thinks a compliant organization looks like. And it explains how to do a HIPAA risk analysis for a small practice, because most of the practices we work with have a policy binder, a training certificate, and no risk analysis, and they don't know it until someone asks.
Key takeaways
- The February 19 settlement resolves a phishing breach affecting 1,980 patients with a $103,000 payment and a two-year corrective action plan, and the finding was the absent risk analysis.
- OCR's corrective action plans follow a fixed sequence: risk analysis, risk management plan, updated policies, workforce training, reporting to OCR.
- A risk analysis is an inventory of where ePHI lives, the threats to each location, the controls in place, and a rated list of the gaps, in writing.
- A small practice can complete a credible first risk analysis in a few weeks with the practice manager, the IT vendor and a template.
- The document has to be updated when systems change and reviewed at least annually; a five-year-old analysis is treated as none.
What the settlement requires
OCR's resolution agreement with the treatment center includes a corrective action plan that OCR will monitor for two years. Based on the announcement, the center must conduct an accurate and thorough risk analysis of the potential risks and vulnerabilities to the confidentiality, integrity and availability of its ePHI; develop and implement a risk management plan to address the risks identified; review and update its written policies and procedures to comply with the Security Rule; train its workforce on those policies; and report to OCR on its progress during the term.
| Corrective action plan element | What it means for the organization |
|---|---|
| Risk analysis | A written assessment covering every system, device and location where ePHI is created, received, maintained or transmitted |
| Risk management plan | For each identified risk, a documented decision to reduce it, and the control, owner and date |
| Policies and procedures | Security Rule policies that match how the organization actually operates, reviewed and approved |
| Workforce training | Training on the updated policies, with records of who completed it and when |
| Reporting to OCR | Submission of the documents above for OCR review, and periodic reports for the two-year term |
Read that table as a description of what OCR expects every covered entity to already have. The settlement makes the center do, under supervision, what it should have done on its own. The cost of doing it voluntarily is the same list of tasks without the $103,000 and without a federal agency reading your policies for two years.
Why phishing keeps leading to this finding
An email account breach is the single most common way a small provider ends up on the OCR portal. Staff email accounts hold patient names, appointment details, scanned insurance cards, lab results forwarded from a portal, and messages to and from patients. When an attacker gets the password, everything in the mailbox is exposed, and the organization has to assume it was all viewed.
The risk analysis connection is direct. An organization that had inventoried where its ePHI lived would have listed email. Having listed email, it would have asked what protects it, and the answer "a password" would have been rated a high risk. The obvious control, multifactor authentication, costs almost nothing. The center did not have the analysis, so it never had the conversation, and the first time anyone rated the risk of a phished mailbox was after the breach.
That chain of reasoning is why OCR treats the missing analysis as the root cause. It is not that the analysis would have prevented the attack by itself. It is that the analysis is the process by which the organization would have noticed the gap.
How to do a HIPAA risk analysis for a small practice
Start with the inventory. List every place ePHI is created, received, stored or sent. For a typical practice: the EHR and practice management system (cloud-hosted or on a server), email, the patient portal, the phone system's voicemail and text features, fax (including e-fax services), workstations and laptops, mobile phones staff use for work, the clearinghouse and billing vendor connections, cloud file storage, backup media, scanners and copiers with hard drives, and paper records for the transition to electronic. Write down for each one where it is, who manages it and who can access it.
Then, for each item, list the realistic threats: phishing and credential theft, ransomware, lost or stolen devices, a departing employee retaining access, a vendor breach, hardware failure without backup, accidental disclosure by misdirected message. Next to each threat, write down the controls that exist today, honestly. Multifactor authentication on or off. Encryption on the laptops or not. Backups tested or not. Access removed on the last day or "eventually."
Now rate each risk: how likely, how bad. A simple high, medium, low on both axes is enough. The items that are high on both are your risk management plan. For each, write the control you will add, who owns it and by when. That set of documents, the inventory, the threats and controls, the ratings, and the plan, is a risk analysis. It does not need to be long. It needs to be true, dated, and signed by whoever is accountable.
HHS publishes a free Security Risk Assessment tool aimed at small practices that walks through this structure question by question, and it is a reasonable place to start. Your IT vendor should participate, but the practice must own the result; OCR settles with covered entities, not their IT companies. Our technology team is often asked to help practices with the inventory step, because websites, online forms and patient messaging tools are the items practices most often forget they have.
Keeping it alive
The Security Rule does not set an interval for updating the risk analysis, but OCR's guidance and every settlement make the expectation clear: update it when something changes (a new EHR, a new location, a move to remote work, a new vendor) and review it at least annually. Put a date on the calendar. Each review should record what changed, which risks were closed, and which new ones appeared.
Keep the evidence. Training completion records, the vendor list with business associate agreements, the multifactor authentication rollout email, the backup restore test log. When OCR investigates a breach, its first letter asks for the risk analysis and the risk management plan, and its second asks for proof the plan was carried out. A practice with a folder that answers both letters is in a very different position from one that has to start writing.
We also tell practices to write the analysis as if a reader who has never visited will use it. The practice manager who built it will leave someday. The document should let the next person understand the systems, the risks and the decisions without a phone call.
Questions we hear
Our IT company says they did a risk assessment. Is that our risk analysis?
Look at it. A vulnerability scan or a network assessment is a useful input, but a HIPAA risk analysis covers the whole organization's ePHI, including workflows, people and paper, not just the network. If the document doesn't inventory where ePHI lives and rate the risks to each location, it isn't the analysis OCR asks for, and the covered entity is responsible either way.
We are a small practice with five employees. Does OCR really look at us?
The February 19 settlement involved a breach of 1,980 patients. The Risk Analysis Initiative has included small providers repeatedly. OCR investigates every large breach reported, and the risk analysis is the first document it requests. Size does not exempt anyone from the requirement.
Do we need a consultant?
Not necessarily. A practice manager with the HHS tool, the IT vendor's help and a few weeks can produce a credible first analysis. A consultant helps when the environment is complicated or when nobody in the practice has the time. Whoever does it, the practice signs it and owns the plan.
What to do this week
- Locate your most recent written risk analysis and check its date; if it is older than a year or does not exist, schedule the work.
- Start the ePHI inventory with the twelve categories listed above, adding anything unique to your practice.
- Turn on multifactor authentication for email today, for every account, before the analysis is finished.
- Ask the IT vendor for a written summary of current controls: encryption, backups, patching, access removal.
- Set the annual review date on the compliance calendar and name the owner.
