Small Breaches Matter Too: OCR Broadens HIPAA Breach Investigations
Healthcare Alert | 2 min read
Aug 26, 2016
The Regional Offices of the Department of Health and Human Services Office for Civil Rights (OCR) already investigate every reported Health Insurance Portability and Accountability Act (HIPAA) breach affecting 500 or more individuals, but now they will intensify efforts to scrutinize smaller breaches too. According to OCR, the root causes of small breaches may indicate entity-wide and industry-wide noncompliance with HIPAA regulations. By investigating the breaches of fewer than 500 individuals, OCR can evaluate an entity's compliance programs, obtain correction of any deficiencies, and better understand compliance issues in HIPAA regulated entities.
For breaches involving less than five hundred individuals, a covered entity is required to maintain a log and collectively report to OCR all such breaches occurring during a calendar year within sixty days of the end of the calendar year. OCR regional offices still retain discretion to prioritize which smaller breaches to investigate. In assessing breaches, the factors OCR Regional Offices will consider include:
- The size of the breach;
- Theft of or improper disposal of unencrypted PHI (protected health information);
- Breaches that involve unwanted intrusions to IT systems (for example, by hacking);
- The amount, nature and sensitivity of the PHI involved; and
- Instances where numerous breach reports from a particular covered entity or business associate raise similar issues.
Regions may take into account the lack of small breach reports when comparing a specific covered entity or business associate to others that are similarly situated. OCR regional offices may also consider covered entities with multiple small breaches as a better target of an investigation.
What It Means for You
The announcement emphasizes the importance of HIPAA compliance and the continued rise of HIPAA enforcement. Covered entities and business associates should assess, audit, and monitor HIPAA compliance on a regular basis, and any entity that reports a breach should be prepared for an audit and/or investigation. HIPAA financial penalties can be substantial, so all reasonable safeguards to avoid HIPAA privacy or security breaches should be instituted.
Hinshaw attorneys have significant experience in advising health care organizations on HIPAA privacy and security compliance matters. For further information, please contact Michael A. Dowell or your regular Hinshaw attorney.
This alert has been prepared by Hinshaw & Culbertson LLP to provide information on recent legal developments of interest to our readers. It is not intended to provide legal advice for a specific situation or to create an attorney-client relationship.
Related People
Related Capabilities
Featured Insights

In The News
Aug 24, 2026
David Schultz Reviews a Humorous—But Important—FDCPA Procedural Ruling

Press Release
Aug 20, 2026
115 Hinshaw Lawyers Recognized in 2027 Editions of The Best Lawyers in America® and Ones to Watch®

Press Release
Aug 20, 2026
Hinshaw’s Landmark Tower Client Project Receives 2026 Top Projects Award

Press Release
Aug 19, 2026
Fernando Rivera-Maissonet Elected as HNBA Region II Governor and Board of Governors Member

Employment Law Observer
Aug 17, 2026
Massachusetts’ First Paid Family Medical Leave Act Verdict Yields $4.75 Million Award

Press Release
Aug 13, 2026
Lauren Campisi Recognized as a 2026 BTI Client Service All-Star by BTI Consulting Group

Consumer Crossroads: Where Financial Services and Litigation Intersect
Aug 13, 2026
How Will Banks Be Impacted by the Proposed Regulation O Amendments?

Press Release
Aug 12, 2026
William Cook Honored With the Distinguished Service Award by the Chicago Bar Association

Webinar
Aug 12, 2026
John Ryan Presents on "Understanding what is Covered Under the TCPA Today"

In The News
Aug 12, 2026
Scott Seaman Analyzes California’s New Pleading Standards for Excess Insurance Policy Claims



