Most organizations meet the HHS Office for Civil Rights (OCR) for the first time by letter — a data request arriving weeks or months after a breach report or a patient complaint. What happens next is decided less by what you do after the letter than by what you documented in the years before it. This guide explains how OCR audits and investigations actually work, what investigators ask for first, and how to assemble the evidence file now, while assembling it is cheap.
Audits versus investigations: know which letter you’re holding
People say “OCR audit” loosely, but two distinct processes exist:
- Compliance audits. OCR has statutory authority under HITECH to run a periodic audit program, and it has run formal audit phases historically. These are proactive reviews against an audit protocol, not triggered by any specific event. They have been intermittent, but the authority is standing and OCR has signaled continued interest in using it.
- Compliance investigations. These are the everyday reality — event-driven reviews opened after a breach report, a complaint, or a referral. Every breach affecting 500 or more individuals gets an OCR review as standard practice. Complaints from patients (often about denied records access) and from current or former employees open the rest.
The preparation is nearly identical for both, because both run on the same fuel: your documentation. The difference is emotional temperature — an investigation arrives with a specific incident attached and the presumption that something may have gone wrong.
How an investigation actually unfolds
The typical arc, in plain terms:
- The trigger. You report a breach, or someone files a complaint. Months can pass before anything happens; OCR carries a large caseload, and silence after a breach report means nothing either way.
- The notification letter and data request. A letter identifies the incident or complaint, cites the rules in question, and encloses a numbered list of document demands with a deadline — often two to four weeks.
- Your production. You respond with documents and a written narrative. This is the single most consequential step in the entire process.
- Follow-up. Additional requests, written questions, sometimes interviews or (rarely) site visits.
- Resolution. Most investigations close in one of three ways: closure with no action; closure with technical assistance (a letter explaining what to fix — the most common substantive outcome); or, for serious or systemic findings, a resolution agreement with a monetary settlement and a multi-year corrective action plan under OCR monitoring. Formal civil money penalties exist but are the rare endpoint, generally reserved for non-cooperation or egregious, unresolved cases.
The pattern in published enforcement actions is remarkably consistent: the settlements are rarely about the breach event itself. They’re about what the investigation found underneath — no risk analysis, or one that was years stale; policies that existed on paper but demonstrably weren’t followed; access that was never reviewed; findings identified years earlier and never remediated. The breach opens the door; the program deficiencies drive the outcome.
What investigators ask for first
The initial data request varies with the incident, but a core set appears almost every time. Consider this the table of contents for the file you should be able to produce in 48 hours:
The risk analysis, and its ancestors
The first request, nearly always: your Security Rule risk analysis under 45 CFR 164.308(a)(1) — current version and prior versions across the retention period. Investigators are checking three things: does it exist, is it real (an enterprise-wide analysis covering all ePHI, not a vendor’s generic checklist with your logo on it), and is it alive (updated as systems and threats changed). A risk analysis last touched four years ago answers all three questions badly. The companion request is your risk management plan — evidence that identified risks were actually tracked to remediation, not just cataloged. See our Security Rule guide for what a defensible analysis contains.
Policies and procedures — with dates
The policies relevant to the incident: access control, encryption, device and media controls, incident response, breach notification, minimum necessary, sanctions. Version history matters, because the question is what policy was in force on the incident date, not what you adopted the week after. The 164.316 documentation standard — written, retained six years, reviewed periodically, available to the workforce — is itself a compliance requirement they evaluate.
Training records
Materials and completion logs, often for specific individuals: “provide evidence that the workforce members involved in the incident completed training, with dates and content.” This is precisely the query that separates a real training program from an annual checkbox — you need to prove that a particular person was trained on a particular policy before a particular date.
The incident file
For breach-driven investigations: the full timeline from discovery to notification, your four-factor risk assessment, copies of the notification letters, evidence of the dates they were sent, and your mitigation and corrective actions. Contemporaneous documentation reads very differently from a narrative reconstructed after the letter arrived — investigators can tell.
Technical and administrative evidence
Depending on the incident: audit logs and access reports for the affected systems, encryption status and evidence for the affected devices, access authorization and termination records, business associate agreements with any vendor involved, and your BAA inventory generally. “Show me the BAA” is a one-document question with no partial credit.
Timelines and the cost of silence
Treat the stated deadline as real. Practical rules:
- Acknowledge immediately and calendar everything. Assign an internal owner the day the letter arrives.
- Ask early if you need more time. Reasonable extension requests, made before the deadline with a credible reason, are often accommodated. Requests made the day before, less so.
- Never ignore the letter. Non-cooperation is an independent aggravator with its own escalation path, up to subpoena authority and penalty proceedings. Some of the worst published outcomes involve entities that simply stopped responding.
- Engage counsel with OCR experience for anything beyond a trivial complaint. The narrative framing of your response — accurate, complete, and organized around the rules cited — is a skill, and privilege considerations around internal analyses need managing from day one.
Responding well: the production itself
A few practices that consistently help:
- Answer the questions asked, in the order asked, with an index mapping each numbered request to the documents produced. Make the investigator’s job easy; a coherent production signals a coherent program.
- Be accurate above all. Never backdate, never “tidy up” a document’s history, never claim a control existed if it didn’t. A gap honestly acknowledged with a remediation plan attached is survivable; a misrepresentation discovered later changes the character of the entire case.
- Show remediation in motion. If the incident exposed a gap, fix it before you respond and document the fix. Voluntary corrective action is explicitly considered in outcomes, and technical-assistance closures generally go to entities that demonstrably fixed what broke.
- Keep one voice. Route all communication with OCR through one designated person or counsel. Well-meaning side conversations create inconsistencies.
Building the audit file before the letter exists
Everything above gets dramatically easier with one habit: maintain a living evidence file, organized the way OCR asks for it. A practical structure:
- Governance: designated privacy and security officers (in writing), current policy set with version history, six-year archive.
- Risk: current risk analysis, prior versions, risk management plan with remediation status and dates.
- People: training content by version, completion records by person and date, signed acknowledgments, sanction policy and any sanction records.
- Access: provisioning and termination records, periodic access review evidence, MFA and encryption configuration evidence.
- Vendors: BAA inventory with signed agreements — both directions if you’re a business associate yourself.
- Incidents: log of all security incidents (including non-breach incidents), risk assessments, notifications, corrective actions.
- Special environments: if your team is distributed, the remote-work policies and device evidence covered in our remote work guide — an increasingly common line of questioning.
Every document in that file is one you’re already required to create and retain under 164.316. The audit file isn’t extra work; it’s the same work, filed findably. Our template library maps to this structure deliberately, and a compliance platform that timestamps evidence as it’s generated makes the “produce it in 48 hours” standard routine rather than heroic — see how the options stack up on our comparison page.
Run the drill: a self-audit twice a year
The cheapest OCR preparation is pretending to be OCR:
- Pull a published OCR audit protocol or a realistic data request list and issue it to yourself with a two-week deadline.
- Attempt the production for real: locate every document, check its date, note every gap.
- Grade honestly: Could you produce the current risk analysis today? Training evidence for a specific employee hired 18 months ago? The BAA for your email vendor? Termination records for last quarter’s departures?
- Convert every miss into a remediation item with an owner and a date — and keep the record of the drill itself, which is exactly the kind of “periodic evaluation” evidence (164.308(a)(8)) that strengthens a program’s story.
A word on vendors promising to make you “HIPAA certified” so audits become painless: no such status exists. HHS certifies no one, and OCR gives no weight to third-party badges. What OCR weighs is the thing certifications pretend to substitute for — a real risk analysis, real safeguards, real records. An independent assessment and readiness report is genuinely valuable preparation; a certificate is wall art.
Start with an honest baseline
The uncomfortable truth about OCR preparation is that it’s just HIPAA compliance, done continuously and filed properly. If your program would struggle with the 48-hour production test, better to learn that from a self-assessment than from a federal letter. Our free HIPAA readiness assessment benchmarks you against the same domains an investigator probes first — risk analysis, policies, training, access, incident response — and shows you the gaps in about ten minutes. If the letter has already arrived, or you want a practitioner to pressure-test your evidence file before one does, book a 20-minute call. The best time to prepare was when you adopted your first policy; the second-best time is before the mail comes.