The most common HIPAA violation in medical offices isn’t caused by hackers. It is one caused by never writing one specific document.

In December 2024, the U.S. Department of Health and Human Services’ Office for Civil Rights (“OCR”) announced a $250,000 settlement with Inmediata Health Group, a “clearinghouse” (an intermediary that converts medical claims into the standard format insurance plans require) based in Puerto Rico that processes data for physicians, dentists, hospitals, laboratories, and health plans across the island.
What happened? Between May 2016 and January 2019, the health information of 1,565,338 people held by Inmediata became publicly accessible on the internet due to a website misconfiguration. That information included names, dates of birth, addresses, Social Security numbers, medical diagnoses, and treatment information — all indexed and accessible through Google.
OCR identified the root cause: Inmediata had never conducted an adequate risk analysis, and it wasn’t monitoring activity on its information systems.
The total cost of this website error was far more than $250,000. Between the OCR settlement, a $1.4 million multi-state settlement with 32 state attorneys general and Puerto Rico, and a $1,125,000 class-action payout, the incident cost Inmediata at least $2.7 million.
$2.7 million in penalties for not having a document required since 2005.
What Is a Risk Analysis, and Why Is It Mandatory?
HIPAA’s Security Rule, at 45 C.F.R. § 164.308(a)(1)(ii)(A), requires every covered entity and business associate to conduct “an accurate and thorough assessment of the potential risks and vulnerabilities” to the confidentiality, integrity, and availability of the electronic health information it handles.
There’s a technical detail here that many people overlook. The Security Rule splits its requirements into 2 categories: requiredand addressable. Required specifications must be implemented by every covered entity and business associate. There’s no flexibility, no alternative, and no exception for the size of the practice. A solo physician’s office has the same obligation as a hospital.
Addressable specifications, on the other hand, do allow flexibility: if your office determines a measure isn’t reasonable given its size, you can document why and adopt an alternative instead.
The Security Rule was designed to account for the size and complexity of your operation, your technical infrastructure, the cost of security measures, and the probability and severity of your risks. A small practice doesn’t need the same analysis as a hospital system. But it needs one.
OCR Is Actively Looking for These Assessments
In October 2024, OCR launched an enforcement initiative dedicated exclusively to this requirement, called the Risk Analysis Initiative. By 2026, it had already announced roughly a dozen enforcement actions.
The reasoning behind focusing on this is fairly simple. These are straightforward cases for OCR: the question they need to answer is: do you have this document or not?
If you’re a HIPAA-covered entity, you need to understand that, if OCR opens an investigation, the first document they’ll ask for is your risk analysis — and most offices can’t produce one.
Being a small practice or business doesn’t protect you from being sanctioned. For example, Bryan County Ambulance Authority (“BCAA”), an entity serving just over 14,000 people, was the first case under this initiative. It settled with HHS for $90,000 following a ransomware attack. The investigation concluded that BCAA had never conducted an adequate risk analysis. Similarly, West Georgia Ambulance, an ambulance company in Carroll County, Georgia, paid $65,000 to HHS in a settlement for failing to conduct a risk analysis, failing to maintain a security awareness training program for its employees, and failing to implement policies and procedures for the Security Rule. 500 individuals were affected by this incident.
OCR recently expanded its investigative focus from “risk analysis” to “risk management.” As a result, the question is no longer just “do you have the document?” but “can you show you acted on what you found?” An analysis done 5 years ago, filed away and never acted on, could today be seen as nearly as bad as having no analysis at all.
Why Should This Matter to You?
Here are at least 4 reasons:
First: ignorance isn’t a defense. The Security Rule has been in force for more than 20 years. OCR has been explicit in concluding that not knowing the Rule doesn’t excuse anyone. At best, it might lower the penalty, but it will not eliminate it.
Second: you face double legal exposure. Since the federal HITECH Act was passed, state attorneys general have independent authority to bring civil actions for HIPAA violations. The Inmediata case demonstrates this clearly: OCR collected $250,000 and the multi-state coalition collected $1.4 million for the same underlying facts. These are separate proceedings.
Third: Puerto Rico has an additional obligation. 2005’s Law 111, as amended, covered previously in this blog, applies to you even if you are subject to HIPAA. Its Article 2 defines “personal information file” to expressly include “medical protection protected by the HIPAA Act.” Consequently, complying with the federal notification does not relieve you of the local obligation. Law 111 requires you to report the security breach to DACO (Puerto Rico’s Department of Consumer Affairs) within a non-extendable 10-day period from detecting the breach. DACO is then required to make a public announcement of the incident within the following 24 hours. Compare this with HIPAA, which gives you up to 60 days to notify affected individuals. Puerto Rico’s clock runs much faster and does not give any extensions. Its fines range from $500 to $5,000 per violation, and they do not prevent those affected from separately suing you for damages. We previously explained this law here. Separately, Section 5 of the Federal Trade Commission (“FTC”) Act covers privacy and security representations made to the public, including what your own website says. Between OCR, the state’s attorneys general, DACO and the FTC, a single incident can lead to 4 simultenaous open legal proceedings against you.
Fourth: This one is important, but one that doesn’t show up in any of these settlements. The first thing your cyber-liability insurer will likely ask for if you ever need to file a claim over a data breach is your risk analysis. If you don’t have one, a denied claim could cost you far more than the fine itself.
How Can You Comply with the Law?
A risk analysis isn’t a form you fill out in an afternoon, but it also doesn’t require hiring an international consulting firm. OCR’s guidance identifies the elements it should contain:
- Scope — every system that creates, receives, maintains, or transmits electronic health information. That includes the personal cell phone your front-desk staff uses to schedule appointments, the computer at home, and your website.
- Data collection — where that information lives, who touches it, where it travels.
- Threats and vulnerabilities — from ransomware to a laptop left in a car.
- Current controls — what you have in place today to mitigate each risk.
- Likelihood that each threat will materialize.
- Impact if it does.
- Risk level resulting from combining the two above.
- Documentation — in writing, with dates.
- Periodic review — this isn’t a one-time event.
Here are 3 practical recommendations that you can implement:
- Use the free federal government tool. HHS publishes the Security Risk Assessment Tool, designed specifically for small and mid-sized practices. It walks you through the elements in plain-language questions, and it’s free.
- Don’t forget to review your website. In risk analyses, many medical offices overlook their own website — the security of contact forms, tracking pixels, plugins, and hosting. HHS’s tool won’t ask you about this; you have to add it yourself.
- Document the corrective actions you’ve taken, not just the findings. With OCR’s shift toward risk management, a dated record of what you found, what you did about it, and when, is just as important as the analysis itself.
- Encrypt your devices, even though HIPAA doesn’t require it. Encryption is an “addressable” implementation specification under the HIPAA Security Rule. However, under Puerto Rico’s Law 111, the duty to notify is triggered only if the information was not protected by cryptographic keys beyond a password. Translation: losing a laptop with strong encryption, whose keys were not compromised, doesn’t start the 10-day clock or trigger DACO’s public announcement. This is one of the few measures that can buy you protection under 2 laws at once.
The Bottom Line
The Inmediata case isn’t a story about a sophisticated hack. It was a multimillion-dollar penalty for a website misconfiguration that nobody caught because nobody was checking. That’s exactly what a risk analysis exists to prevent.
If your office handles electronic health information — and if you use electronic billing, email, or a records system, you do — you’ve had this obligation since day one. It doesn’t matter whether you have 2 employees or 200.
The question worth asking today isn’t whether you’ll eventually be investigated. It’s simpler than that: if OCR asked for your risk analysis tomorrow morning, could you produce it?
If your answer is “no” — or “we did one years ago and I don’t know where it is” — it’s worth addressing now, before it becomes a matter of enforcement instead of planning, and before it costs you hundreds of thousands of dollars in penalties, and before your name ends up in newspapers and blogs across Puerto Rico and the mainland U.S. for failing to protect your patients’ information.
Do you have questions about whether your medical practice complies with this HIPAA rule? You can schedule a consultation with us today. We’re here to help.
About the Author
Jaime Farrant is an attorney admitted to practice law in Puerto Rico, New York, Maryland, and the District of Columbia, with an LL.M. in International Law, focusing on privacy, cybersecurity, and AI regulation for businesses and healthcare providers.
ADVERTISING MATERIAL. This article constitutes advertising as defined under the rules of professional conduct in effect in New York (22 NYCRR 1200.7.1 and 1200.7.3), Maryland (Rule 19-307.1 and 19-307.2), and the District of Columbia (D.C. Rules of Professional Conduct 7.1), as well as the Puerto Rico Rules of Professional Conduct (Rules 7.1–7.3). It does not constitute solicitation of known prospective clients who need legal services in a particular matter. Rather, it is general information directed to the public about the practice of law and available legal services. No attorney-client relationship is created by reading this article or by contacting the author.