It is the second week of August. Your Thursday has two cancellations on it, the phone is not ringing, and half the people who would normally email you are at a lake somewhere. This is the slowest stretch of your working year.

It is also long enough to do the one thing federal investigators keep asking for and not getting.

One Click, and Then a Letter

A treatment center in Illinois. Not a hospital. The kind of place with a handful of clinicians and one person who answers the phone.

Someone on staff opened an email and clicked. That is the whole story of how it started.

Here is the part worth your attention. When the Office for Civil Rights came in afterward, the thing that decided the outcome was not the phishing email. It was a document the practice could not produce.

That has now happened fourteen times in a row.

OCR runs something it calls the Risk Analysis Initiative. Fourteen enforcement actions so far, against practices, vendors, and plans of every size, and in every single one the agency landed on the same finding: no current risk analysis existed before the incident.

Read that as an operations fact rather than a legal one. After something goes wrong at your practice, the first request is not for your firewall configuration or your password policy. It is for one document that shows you had looked at where patient information sits and who can get to it. If you can hand it over, the conversation is about the incident. If you cannot, the conversation becomes about you.

OCR has never asked a small practice to prove it was unhackable. It asks whether you looked.

What Is Actually in Your Drawer

Go look. Most people find one of three things.

Nothing at all.

Or a PDF from 2019 with an EHR vendor's logo on it, produced during onboarding, describing a network you no longer run and a front desk person who no longer works there.

Or a security questionnaire someone filled out for a payer, which is a different document doing a different job.

None of those is a risk analysis. And the gap is not carelessness. It is that "conduct a risk analysis" sounds like it needs a consultant, a scanning tool, and a week you do not have, so it moves to next quarter. Next quarter has patients in it.

Meanwhile the practice keeps changing underneath the old paper. You added an AI scribe. You switched telehealth platforms. Your front desk person left and the new one uses her own laptop. You moved the office. Every one of those changed where charts live and who can reach them, which is the exact thing the document is supposed to describe.

So you can be a careful practice and still be the practice that cannot prove it.

Four Questions, Not a Project

Strip the vocabulary out and it is four questions, answered in writing, with a date on the page.

Where do charts live? Walk your own office and list every place. The EHR. The billing platform. Your phone, if the app is on it. The laptop. The backup drive. The scanner. The filing cabinet. Voicemail. The scribe vendor. Anything that touches a chart.

Who can get to each one? Real names and real vendors, with the access they actually hold rather than the access you meant to give. This is where most people find their first surprise. An old staff login still active. A vendor account nobody remembers creating. One password three people use.

What could go wrong, and how bad would it be? Not a threat catalogue. Your setup. The laptop is stolen. The billing service gets ransomware. Someone phishes the front desk. For each one, how likely, and what walks out the door.

What are you doing about the ones that matter? The protections already in place, the gaps you are accepting for now and why, and the gaps you are closing with a date next to them.

That last question is the one people skip, and it is the one that changes an investigation. A document that names a problem and shows you handled it reads like a practice paying attention. A clean document with no problems in it reads like a form somebody filled out.

The Vault's internal binder includes The Annual HIPAA Risk Assessment as a fill-and-sign module built around those four questions, sized for a practice of one to five people rather than a health system.

Two Hours in the Quietest Week of Your Year

You do not need a week. You need one block, and August is when you have it.

Block two hours on a light afternoon. Not an evening after a full day of patients. An afternoon you are already at the desk with nothing scheduled.

Do the walk first, before you open any template. List every place a chart can be reached, from memory and by looking around. Forty minutes. Doing this before you read a template is what makes you notice the things a template would not have asked about.

Write down what you found, with today's date on it. Including the uncomfortable parts. A line that says "work network not fully separated, fixing by the end of September" is worth more than silence, in an investigation and in September.

Put next August on the calendar before you close the file. The most common failure is not a missing first assessment. It is a first one that never got a second.

If your last one predates your current EHR, your current telehealth platform, or your current office, you do not have a current risk analysis. You have a historical document about a practice that no longer exists.

Those holes in your calendar this month are the best working conditions you will get until January.

The document all fourteen of those cases came down to.
The Vault's internal binder includes The Annual HIPAA Risk Assessment as a fill-and-sign module, built around those four questions and sized for a practice of one to five people. It sits alongside 34 other internal forms, among them the Breach Response Runbook and the Password, Encryption and Access Control Policy. National edition $299. New York edition $349 (adds SHIELD Act and state-specific addenda).
Get the Vault →
With security,
Brad
Brad Lieberman, JD (retired), MSN, PMHNP-BC
Founder, The Encrypted Chart
www.encryptedchart.com · Vault: store.encryptedchart.com/l/binder
Brad@encryptedchart.com
Footnotes
  1. Nixon Peabody LLP, ‘Health plan settlement marks OCR’s 20th ransomware enforcement action and 14th Risk Analysis Initiative enforcement action,’ July 21, 2026.
  2. U.S. Department of Health and Human Services, Office for Civil Rights, Resolution Agreements and Civil Money Penalties.
  3. McDonald Hopkins, ‘OCR announces Risk Analysis Initiative enforcement actions,’ including the Illinois treatment center and dental software vendor resolutions, and the quoted statement of OCR Director Paula M. Stannard.
  4. Risk analysis, a required implementation specification at 45 CFR § 164.308(a)(1)(ii)(A).