Client support portal Pay invoice Sales(615) 555-0110 Support(615) 555-0111
Chartline Health IT
Compliance  ·  08 Jul 2026  ·  7 min

What OCR actually asks for in a data request

Eleven document categories, taken from a real request. Go down the list and mark which ones you could produce this week.

A HIPAA data request is not an audit and it is not an accusation. It is a letter with a list and a deadline, usually thirty days, and the entire question is whether the things on the list already exist.

Here is the list from a request one of our clients received in 2026, following a breach at one of their business associates. It is a fairly standard set.

  1. The current risk analysis, and the methodology used to conduct it.
  2. The risk management plan, with evidence that remediation items were completed.
  3. The asset inventory and the ePHI data-flow map.
  4. Workforce security training records, with dates and role assignments.
  5. The business associate register, with executed agreements.
  6. Access review and workforce termination records.
  7. Audit log samples for the systems in scope.
  8. The incident response plan, and evidence that it has been tested.
  9. Encryption status for devices and media.
  10. Policies and procedures, with version history.
  11. Prior incident history.

The only question that matters

Not whether you have controls. Whether you have artifacts, dated before the request arrived.

This is the part that surprises people. A practice can have genuinely good security — enforced multi-factor authentication, endpoint detection everywhere, immutable backups, a competent IT provider — and still be in a difficult position, because none of that produces a document unless somebody decided it should.

And the dates matter enormously. An investigator reading a risk analysis dated two weeks after the data request understands exactly what happened. It is not that a late artifact is worthless. It is that it answers a different question than the one being asked.

Go down the list

Mark each one: could produce this week, could produce with effort, does not exist. Be strict — "our IT company probably has that somewhere" is does not exist, because a thirty-day clock does not care where it probably is.

Most practices we assess can produce three or four of the eleven. The ones that can produce all eleven have generally been through something already.

What a good answer looks like

In our engagement, all eleven categories already existed as maintained, dated artifacts. Nothing was created after the request arrived. The evidence-gathering took under two days; the remaining seven of the nine business days were the client's counsel reviewing the package and our vCISO writing the narrative explaining how the artifacts related to one another.

The response also included a Recognized Security Practices attestation covering twelve rolling months, submitted under the HITECH amendment signed January 5, 2021. Where a regulated entity demonstrates Recognized Security Practices were in place enterprise-wide for the previous twelve months, OCR must consider that as a mitigating factor. The matter closed without penalty and without a corrective action plan.

None of that was clever. It was just already done.

Next step

See where you actually stand.

Fifteen questions, each mapped to a Security Rule citation. You get a scored result naming the specific §164 requirement behind every gap. No call required to see it.

Under attack right now? (615) 555-0119

Our incident line is answered 24/7/365 by a security engineer, not a queue. Clients and non-clients both. If you are mid-incident, call before you email.