What OCR actually asks for in a data request
Eleven document categories, taken from a real request. Go down the list and mark which ones you could produce this week.
A HIPAA data request is not an audit and it is not an accusation. It is a letter with a list and a deadline, usually thirty days, and the entire question is whether the things on the list already exist.
Here is the list from a request one of our clients received in 2026, following a breach at one of their business associates. It is a fairly standard set.
- The current risk analysis, and the methodology used to conduct it.
- The risk management plan, with evidence that remediation items were completed.
- The asset inventory and the ePHI data-flow map.
- Workforce security training records, with dates and role assignments.
- The business associate register, with executed agreements.
- Access review and workforce termination records.
- Audit log samples for the systems in scope.
- The incident response plan, and evidence that it has been tested.
- Encryption status for devices and media.
- Policies and procedures, with version history.
- Prior incident history.
The only question that matters
Not whether you have controls. Whether you have artifacts, dated before the request arrived.
This is the part that surprises people. A practice can have genuinely good security — enforced multi-factor authentication, endpoint detection everywhere, immutable backups, a competent IT provider — and still be in a difficult position, because none of that produces a document unless somebody decided it should.
And the dates matter enormously. An investigator reading a risk analysis dated two weeks after the data request understands exactly what happened. It is not that a late artifact is worthless. It is that it answers a different question than the one being asked.
Go down the list
Mark each one: could produce this week, could produce with effort, does not exist. Be strict — "our IT company probably has that somewhere" is does not exist, because a thirty-day clock does not care where it probably is.
Most practices we assess can produce three or four of the eleven. The ones that can produce all eleven have generally been through something already.
What a good answer looks like
In our engagement, all eleven categories already existed as maintained, dated artifacts. Nothing was created after the request arrived. The evidence-gathering took under two days; the remaining seven of the nine business days were the client's counsel reviewing the package and our vCISO writing the narrative explaining how the artifacts related to one another.
The response also included a Recognized Security Practices attestation covering twelve rolling months, submitted under the HITECH amendment signed January 5, 2021. Where a regulated entity demonstrates Recognized Security Practices were in place enterprise-wide for the previous twelve months, OCR must consider that as a mitigating factor. The matter closed without penalty and without a corrective action plan.
None of that was clever. It was just already done.
Your imaging server is probably on the internet
A late-2025 scan found 3,627 internet-accessible DICOM servers. CVE-2025-0896 is why the free ones are over-represented.
Read it Compliance · 24 Jun 2026What a real risk analysis contains, and what the SRA Tool produces
A completed HHS Security Risk Assessment Tool questionnaire is not a risk analysis. OCR settlements have said so repeatedly. Here is the difference.
Read it