The 10 HHS Audit Findings Most-Cited at Healthcare Organizations in 2026
Five Nines Executive Team : Sep 18, 2026, 6:00:00 AM
5 min read
The HHS Office for Civil Rights publishes Resolution Agreements, Corrective Action Plans, and aggregated audit findings on a continuing basis. The pattern across healthcare organizations examined or settled with in the last several years is consistent. The same ten findings appear again and again.
Most of these are not exotic technical failures. They are governance and discipline gaps that show up as documentation failures, missing reviews, and out-of-date records. Each is fixable with budgeted operating discipline, and each is cited because the organization could not produce evidence the discipline operates.
The CEO question is not whether the organization can avoid these findings forever. It is whether the organization's compliance program is structured to surface them internally, before HHS does, and to fix them on the organization's own timeline rather than under a Corrective Action Plan.
What This Year's HIPAA Enforcement Record Has in Common
The pattern is not subtle. HHS is not citing novel technical failures. The agency is citing the same governance and discipline gaps repeatedly, often at organizations whose IT teams are technically competent and whose tooling is current.
The reason for the consistency is that the HIPAA Privacy Rule, Security Rule, and Breach Notification Rule together describe a program. HHS investigators look for evidence the program operates. When the program exists on paper but not in operating discipline, the gap is visible to the investigator regardless of how strong the organization's technology stack is. The findings cite the gap, not the technology.
A healthcare CEO who reads the visible enforcement record will recognize the same ten findings cited at peer organizations. The list below is what they look like in practice.
The Ten Findings HHS Cites Most Often — And What Each Requires
The first finding is failure to conduct or update a HIPAA Risk Analysis. The Security Rule requires the analysis. HHS asks for it during enforcement. Investigators cite analyses that are years out of date, that do not cover newer systems and vendors, or that exist as a checklist without actual risk identification. The fix is a maintained analysis, updated when the organization adds systems or vendors, with a documented review cadence and named owner.
The second finding is failure to encrypt ePHI on devices and backup media. The Security Rule frames encryption as "addressable" rather than "required" under the current rule, but HHS treats unencrypted devices containing ePHI as nearly-automatic findings unless the organization has documented why an alternative measure was chosen. The fix is universal encryption with a documented inventory and explicit exception management.
The third finding is failure to implement appropriate access controls. The rule requires the organization to limit access to ePHI based on role and need. Investigators cite organizations where former employees retained access weeks after departure, where role-based access controls drifted, where privileged accounts were not separated from ordinary accounts, and where access reviews happened either rarely or never. The fix is a quarterly access review with documented outcomes and a privileged-access discipline that survives staff turnover.
The fourth finding is failure to monitor and review audit logs. The organization's systems generate logs by default. The Security Rule requires monitoring activity in systems containing ePHI. Investigators cite organizations that have logs but no documented review function, no named owner, and no response procedure when logs surface anomalies. The fix is to budget the review as a defined operational responsibility, internally or with an external partner.
The fifth finding is failure to implement multi-factor authentication on systems containing ePHI. The rule treats authentication as a flexible standard, but HHS enforcement increasingly treats MFA as the expected baseline, and the proposed Security Rule revisions name MFA explicitly. Investigators cite organizations where MFA covers some accounts but not others, where configurations include exceptions that swallow the rule, and where the organization cannot demonstrate enforcement across all systems containing ePHI. The fix is policy-level enforcement with documented exceptions minimized.
The sixth finding is inadequate vendor risk management. The rule requires Business Associate Agreements with vendors handling ePHI, with appropriate flow-down to subcontractors. Investigators cite organizations whose BAAs are missing for material vendors, whose vendor inventories do not match their actual third-party relationships, whose vendor reviews happen sporadically, and whose contracts do not flow down equivalent safeguards downstream. The fix is a vendor risk program operating as a recurring function with documented cadence.
The seventh finding is failure to provide workforce training. The rule requires training, and the rule's authors expect training to actually change behavior. Investigators cite organizations where training is delivered once at hire and never repeated, where training does not cover the specific risks the organization faces, and where the organization cannot demonstrate completion or retention. The fix is annual training tailored to the organization's actual risk profile, with completion tracked and remediated.
The eighth finding is inadequate incident response. The rule requires the organization to develop and implement an incident response plan covering preparation, detection, analysis, containment, eradication, recovery, and post-incident review. Investigators cite organizations whose plans are out of date, whose incident response was ad-hoc when an event occurred, whose breach notification timelines were missed, and whose post-incident analysis did not produce remediation. The fix is a tested, documented plan with regular exercises.
The ninth finding is missing or inadequate Privacy Rule compliance. The Privacy Rule governs use and disclosure of protected health information. Investigators cite organizations whose Notices of Privacy Practices are out of date, whose minimum-necessary practices do not match their actual workflow, whose patient access procedures fail, and whose accounting-of-disclosures records are incomplete. The fix is operational discipline at the workflow level, not just at the documentation level.
The tenth finding is missing or inadequate Breach Notification Rule compliance. When breaches occur, the rule requires specific notification timelines, content, and recipients. Investigators cite organizations whose breach response missed the sixty-day notification window, whose notifications were incomplete or inaccurate, whose HHS notifications were delayed, and whose media notifications (where applicable) were missed. The fix is a documented breach response procedure with named owners and tested timelines.
Why the Real Gap Is Discipline, Not Technology
Read across the ten findings, the common thread is not technical inadequacy. It is the gap between the program an organization says it runs and the evidence the program actually operates. Every cited finding is, at root, a documentation-and-discipline gap rather than a technology gap.
That pattern matters for the CEO because it changes what the budget needs to fund. If the findings were technical, the fix would be tooling. The fix is operating discipline, which means the budget needs to fund the people, the cadence, and the documentation that produce evidence the program runs. That is harder to justify than tooling, and it is what HHS investigators actually examine.
A CEO who funds tooling without funding discipline produces an organization that looks well-equipped on the IT side and well-cited on the enforcement side. A CEO who funds discipline alongside tooling produces an organization that survives investigation.
Why "We Haven't Been Investigated" Is the Wrong Measure of Readiness
A healthcare CEO will hear, somewhere in the budget conversation, this argument: the organization has not been investigated by HHS, the program is functionally adequate, and increasing investment in compliance discipline is solving a problem that has not yet materialized.
That is a false choice, and the enforcement record makes it expensive to keep believing in. HHS settlements over the past several years have reached organizations of every size, often after years of operation without any enforcement attention. The trigger is rarely planned by the organization. It is a breach the organization disclosed, a complaint from a patient or former employee, or a referral from another regulator. By the time the trigger arrives, the program either operates with discipline or it does not. The investment decision precedes the trigger, not the other way around.
The right framing is not whether the organization has been investigated. It is whether the organization's program would survive an investigation if one occurred next quarter. The first framing produces complacency. The second framing produces preparation.
The Ten-Finding Benchmark That Changes the Budget Conversation
A defensible approach involves healthcare partner through a current-state benchmark against the ten common findings.
The exercise produces a one-page status indicator for each finding, with evidence of the organization's current discipline (or the gap, where it exists). The CEO uses the document to set priorities for the next budget cycle and to brief the board.
Organizations that complete this exercise on a recurring cadence find that an HHS investigation, when it happens, shifts from a multi-year crisis to a manageable response. The findings the investigation surfaces are findings the organization had already identified and was addressing. The discussion with HHS moves from "we did not know" to "we knew, and here is what we did about it." The first response invites a Corrective Action Plan. The second response usually closes the finding without one.
Address the Ten Findings Before HHS Does It for You
A healthcare CEO who reads the ten common findings is reading the categories the next HHS investigation is likely to evaluate. The organization that addresses each category before investigation arrives presents a defensible program. The organization that does not addresses them under a Corrective Action Plan, on HHS's timeline, with executive attention diverted from the strategic agenda for years.
If your healthcare organization has not produced a current-state benchmark against the ten common findings in the last twelve months, that is the conversation worth having with your Tech-Operations partner before the next regulatory cycle.
Five Nines Technology Group is the Tech-Operations partner serving hospitals, clinic systems, and healthcare practices across the region. We focus on helping CEOs and boards turn enforcement patterns into operating discipline, so the next investigation reflects a program the organization chose to run, not the gaps an investigator chose to find.
Frequently asked questions
Are these ten findings specific to small clinics, or do hospitals see them too?
Hospitals see the same categories at greater scale, with different specifics. The ten categories are the framework. The detail at any given organization depends on its size, complexity, and operating model.
How does HHS find an organization to investigate?
Most enforcement actions originate from one of three sources: a breach report the organization filed, a complaint from a patient or former employee, or a referral from another regulator. HHS is not actively scanning. It responds to triggers, and the triggers exist whether the organization is large or small.
How does the proposed Security Rule revision affect these findings?
The revisions strengthen several of the categories above (encryption from "addressable" to "required" in defined contexts, MFA mandates, vendor flow-down, audit-log requirements). Findings that exist under the current rule would likely be cited more aggressively under the revised rule.
Does external auditing catch these issues before HHS does?
Often, depending on the auditor's scope. HIPAA-specific audits, HITRUST assessments, and SOC 2 reviews each catch different subsets of these findings. Organizations that combine multiple audit lenses tend to surface more gaps than organizations relying on a single review type.
What is the typical Resolution Agreement amount for these findings?
Highly variable, with small-clinic settlements clustering in the low six figures and hospital-system settlements running substantially higher. The amount depends on the severity, the number of affected individuals, the organization's culpability, and the corrective action required.
What is the most common root cause across all ten findings?
The most common root cause is the absence of named ownership for each program function. Without a documented owner, the function drifts. With a documented owner accountable to the governing body, the function survives the personnel changes and operational pressures that would otherwise erode it.
How often should the organization self-assess against these finding categories?
Annually at minimum, with deeper review every two years that includes external assistance. The discipline of self-assessment is what makes the next regulatory interaction routine rather than a fire drill.