The majority of HIPAA fines don't result from sophisticated cyberattacks or deliberate misconduct. They come from documentation gaps that OCR identifies in the first 30 minutes of an investigation. Most practices are running reasonable security operations but have never organized the paperwork that proves it — and in a regulatory context, undocumented compliance is non-compliance.

Here's what OCR actually requests and what they expect to find.

How OCR investigations start

Most investigations are triggered by one of three sources: a patient complaint filed directly with HHS, a breach notification submitted by the practice, or a proactive audit. The vast majority are complaint- or breach-driven — meaning something already went wrong before OCR got involved.

When OCR opens a case, they issue a data request within days. That request is standardized. It asks for specific documents that must be produced, typically within 30 days. What you have on file at that moment determines whether the investigation is resolved quickly or escalates into a Resolution Agreement with financial penalties.

The six document categories OCR requests first

1
Security Risk Analysis (SRA)

The single most cited deficiency across all OCR investigations. Must be current (within 12 months or since last significant change), must cover all ePHI across all systems, and must include documented risk ratings and a corresponding management plan. A verbal process or IT vendor report does not satisfy this requirement.

2
Risk Management Plan

The SRA produces findings. The Risk Management Plan documents what the practice is doing about them. OCR expects to see prioritized risks, assigned owners, timelines, and evidence of implementation. A plan that was written but never acted on is worse than no plan — it demonstrates awareness of the risk without remediation.

3
Written HIPAA Policies and Procedures

The Security Rule requires written policies covering access controls, device and media controls, workforce security, audit controls, and more. OCR requests these and checks whether they reflect actual operations — not boilerplate downloaded from the internet five years ago. Policies must be reviewed and updated regularly.

4
Workforce Training Records

HIPAA requires that all workforce members who handle PHI receive regular training. OCR expects documented evidence — not just a statement that training occurred. Attendance records, training content, completion dates, and attestation signatures. Annual recurrence. New hire training within a defined period of start date.

5
Business Associate Agreements

OCR requests a current list of all business associates and copies of executed BAAs for each. Missing BAAs — or BAAs that don't meet the regulatory requirements — are cited as violations independent of whether a breach occurred. Every vendor, contractor, or service provider who accesses PHI must have a signed, compliant BAA on file.

6
Breach Log

Covered entities must maintain a log of all breaches affecting fewer than 500 individuals — these are reported annually to HHS. OCR reviews this log for completeness and for evidence that incidents were investigated and addressed. A missing or incomplete breach log raises immediate questions about incident detection capability.

The pattern in Resolution Agreements

Review any OCR Resolution Agreement from the last five years and you'll see the same findings: no SRA, or an outdated one. Policies that exist on paper but weren't followed. Training records that can't be produced. BAAs that were never signed with one or more vendors. The fines range from $50,000 to over $1,000,000 — not because practices were reckless, but because documentation was never organized as a compliance priority.

What "audit-ready" actually looks like

Audit-readiness doesn't mean perfection. It means that when OCR sends a data request, your practice can produce a current SRA, a corresponding Risk Management Plan with evidence of implementation, written policies reviewed within the last 12 months, training records for all staff, a complete BAA file for all vendors, and a breach log.

Most practices have some of these. Almost none have all of them organized, current, and defensible on 30 days' notice. The goal of a compliance engagement is to close that gap — not to achieve theoretical perfection, but to reach a documented state that OCR will accept as good-faith effort.

The AI complication

AI tools have introduced a new documentation gap that most practices haven't addressed: AI systems touching ePHI that are not in scope for the SRA, don't have BAAs, and haven't been reviewed by anyone with compliance authority. OCR has signaled this as a growing enforcement priority. If your practice adopted any AI tools in the last 18 months — scribes, chatbots, billing automation, clinical decision support — those tools need to be in your documentation now, before OCR asks.