Skip to content
Hipsana

Articles / If something happened

What Happens If a Dental Practice Fails a HIPAA Audit? (2026)

A surprise HIPAA audit almost never ends in a fine. What actually costs a dental practice five or six figures is the OCR investigation that follows a breach or a complaint, and it usually comes down to one document many practices never finished: the risk analysis. Here is what that process really looks like and how to get ahead of it. An OCR investigation weighs your whole program, not a single form, so it helps to first see the full set of HIPAA rules a dental practice follows.

This article explains what happens if a dental practice fails a HIPAA audit. It is general information, not legal advice for your specific situation. For that, consult a healthcare attorney or a qualified HIPAA compliance professional.

In late 2021, an Oklahoma emergency medical provider was hit by ransomware that locked records for roughly 14,000 patients. The provider, Bryan County Ambulance Authority, reported the breach to OCR, as the law required. OCR opened an investigation and found one decisive thing: it had never conducted a compliant risk analysis, the basic security review HIPAA requires of every covered practice. The matter settled for $90,000 and three years of federal oversight (HHS, October 2024). It is an ambulance service, not a dental office. But the failure OCR cited has nothing to do with ambulances, and everything to do with one of the most common Security Rule gaps it finds in small practices of every kind.

Excerpt from the U.S. HHS Office for Civil Rights announcement of the $90,000 Bryan County Ambulance Authority settlement, showing OCR's finding that the provider had failed to conduct a compliant risk analysis.
OCR's first Risk Analysis Initiative settlement: Bryan County Ambulance Authority paid $90,000 after OCR found it had never conducted a compliant risk analysis. Source: HHS / OCR, October 31, 2024.

First, what a “HIPAA audit” really is (and isn’t)

Most dentists picture an audit as an official appearing unannounced to fine you for a missing box. That is not how the money usually changes hands. OCR runs a formal HIPAA Audit Program under the HITECH Act, but it is small and periodic: the 2016-2017 round reviewed about 200 organizations, and the current round, restarted in late 2024, covers just 50, focused on the Security Rule provisions most relevant to hacking and ransomware attacks (HHS). Across hundreds of thousands of practices, the odds yours is randomly selected in a given year are low.

Here is the part that surprises people. OCR frames the audit program as a way to improve compliance, not to punish. When the HHS Office of Inspector General reviewed the 2016-2017 round in 2024, it found the audits were too narrowly scoped to effectively assess protections, and that OCR's oversight of the program was not effective at improving cybersecurity at the entities it audited. The thing most owners fear, failing a surprise audit, has historically carried no fine at all.

What actually puts a practice at financial risk is an OCR investigation, a different process with a different trigger. It starts when:

  • A patient or staff member files a complaint with OCR, or
  • You report a breach of unsecured patient information, which the Breach Notification Rule requires (45 CFR §§164.400-414). Breaches affecting 500 or more people are also posted on OCR’s public portal, the “Wall of Shame.”

The resumed audit program adds one wrinkle: if an audit surfaces a serious problem, OCR can convert it into an investigation. But the dominant path to a penalty still runs through the breach you report or the complaint a patient files, not a random knock on the door.

What an OCR investigation actually looks like

The Bryan County case is a clean map of the process, and of the timeline.

The trigger

Ransomware encrypted the provider's files in November 2021. It reported the breach to OCR in May 2022.

OCR opens an investigation

In June 2022, weeks after the breach report, OCR opened its review.

One document comes first

After a breach, one of the first things OCR asks for is your risk analysis and when you last completed it. It is the required written exercise of finding where patient data lives and what could go wrong with it (45 CFR §164.308(a)(1)(ii)(A)).

OCR makes findings

Here it was blunt: no evidence of a compliant one.

Resolution

Most matters end in a Resolution Agreement, a settlement plus a Corrective Action Plan, with no admission of wrongdoing. Bryan County paid $90,000 and accepted a plan OCR monitors for three years. A formal Civil Money Penalty is reserved for the worst cases.

Two things catch practices off guard. It is slow: Bryan County's 2021 breach did not settle until late 2024, and another 2024 case ran roughly six years from breach to resolution. And the corrective action plan, not the check, is what people underestimate. It is a multi-year commitment, supervised by the government, to fix what they found.

What “failing” actually costs

The honest numbers are smaller than the headlines and larger than most owners assume. In October 2024, OCR launched a Risk Analysis Initiative to focus investigations on this one requirement, and within six months it had announced five settlements, from small physician groups to national vendors. Nearly all shared Bryan County's gap: no accurate, thorough risk analysis. Four examples:

ProviderSettlementWhat OCR found
Health Fitness Corporation, an employee-wellness vendor$227,816A misconfigured server left records exposed online for about three years; no risk analysis
Deer Oaks, a behavioral health provider$225,000A hacker stole patient records and demanded payment, plus an earlier online exposure of records; no risk analysis
Bryan County Ambulance Authority$90,000Ransomware encrypting records for about 14,000 patients; no risk analysis
A Michigan surgical group$10,000Ransomware that encrypted records for about 15,000 patients; no risk analysis
Recent OCR settlements, every one for the same gap: no accurate, thorough risk analysis. Each also carried a corrective action plan OCR monitors for two to three years. Figures from HHS and OCR announcements.

Each settlement above is documented on HHS.gov: Health Fitness Corporation, Deer Oaks, Bryan County Ambulance Authority, and Northeast Surgical Group.

For a solo or small dental practice, realistic exposure for a serious failure sits in the five-to-six-figure range, not the seven-figure range you may have seen quoted. The multimillion-dollar numbers attach to large organizations or the worst tier of violation. The statutory ceiling is real, the maximum annual penalty for willful neglect left uncorrected is $2,190,294 for 2026 (Federal Register, January 2026), but under OCR's longstanding approach that cap applies in practice only to that worst category. A small practice that reports a breach and shows good-faith effort is not the profile that draws it.

Your practice's facts can change the answer, so for your specific situation, consult a healthcare attorney or qualified compliance professional.

The costs that are not a dollar figure matter too. The corrective action plan means years of work under OCR supervision. If a breach crossed the 500-person line, your practice name sits on a public federal list. For a solo dentist whose reputation is the practice, that can outlast the check.

One dental-specific point is worth knowing, because it is the other common way a dentist ends up in front of OCR. In 2022, dental practices were a focus of OCR's Right of Access enforcement, the rule that requires giving patients a copy of their records, usually within 30 days. That September, OCR settled three dental cases at once, for $30,000, $80,000, and $25,000, each over a patient who waited months for records they were owed. So the two paths that most often end in a penalty for a dentist are a reported breach, where the risk analysis is the issue, and a records request the patient had to chase.

OCR's audits are built to improve compliance, not to fine. The money comes from the investigation that follows a breach.

The one document OCR checks first

Step back, and the pattern is hard to miss: the expensive failure is almost never exotic. After a breach, the risk analysis is the first thing OCR asks to see, because it shows whether you were watching your own vulnerabilities before something went wrong. A current, honest one does not make you breach-proof, but it changes the conversation, and the factors OCR weighs when setting a penalty include your compliance history and your good-faith effort to fix problems (45 CFR §160.408).

This is also where most practices quietly fall short. The risk analysis is required of every covered practice, but it is not a twenty-minute form. HHS offers a free Security Risk Assessment Tool, a reasonable place to start, but not a finished assessment that would satisfy an investigator: it gives you the questions, not which answers are wrong in your office. If you have never run one, our guide to the dental HIPAA risk assessment covers what it has to include.

That is the gap the HIPAA Risk Scorecard is built to surface. It checks ten core Security Rule controls that line up with the issues OCR raises most, scores your practice, and follows with a short review and an intro to a specialist if a referral makes sense. It is a starting point, not a formal risk analysis: a few minutes, and you see where you stand before a breach or a complaint forces the question. Check your practice now.

How to get ahead of an investigation

The work is not mysterious. It mirrors what OCR puts in nearly every corrective action plan, which is a fair description of what “good” looks like to them.

  • Do a real risk analysis. Map where patient data lives and what could expose it. Write it down and date it. This is the highest-value step, and the one OCR checks first.
  • Build a risk management plan. An analysis that finds problems and fixes nothing is worse than none. List each gap and how you will close it.
  • Sign real business associate agreements. Every vendor that stores or handles patient data on your behalf, your practice-management software, IT company, billing service, needs one (45 CFR §164.504(e)). Missing BAAs are a recurring finding, and AI tools are the newest place they go missing; here is which AI tools will sign a BAA for a dental practice, and the five-question test to run on any AI scribe vendor.
  • Write your policies, and follow them. “We know what to do” is not a policy. OCR expects documents you can produce.
  • Train your team, and keep the records. A front-desk mistake is the practice's liability. Documented training, kept current, is both a requirement and a defense.
  • Have a breach response plan. Knowing how to report on time keeps a manageable incident from becoming a Breach Notification Rule violation on top of the breach, and we walk through the first 60 days after a dental data breach step by step.

None of these is expensive alone, and what a dental HIPAA risk assessment actually costs ranges from free with the federal tool to a specialist's fee. What makes them feel impossible is not knowing which you are missing, which is the whole reason the risk analysis comes first.

The catch: a few things that are easy to get wrong

“We’re too small to be on OCR’s radar.” The Risk Analysis Initiative reached small physician groups, and one settlement for this failure was $10,000, a number that only makes sense for a very small organization. OCR’s position is that no entity is too small for the requirement.

“Reporting my own breach just invites a fine.” Not reporting is far worse. A failure to notify is its own violation, and hiding a breach is the kind of conduct that pushes a case toward willful neglect. The practices that fare best report promptly and show they had done the groundwork.

“A clean audit means I’m fine.” The audit and an investigation test different things. The audit is a documentation review of a handful of practices. The investigation is what happens after a real breach or complaint, and that is where the money is.

This is general information, not legal advice. Hipsana is not a law firm, a compliance officer, or a healthcare provider. Verify current requirements with HHS or qualified counsel before acting.

About the author

Dolev Arama is Hipsana's founder. He's the one behind the Scorecard and the short risk reviews it produces. He is not an attorney, and Hipsana is a publisher and referral service, not a law firm or a healthcare provider. The writing here starts where the rules actually live (HHS, OCR, NIST) and gets checked against their current text before it goes up. Regulatory claims trace back to those sources, and figures name where they come from; anything that can't be verified is labeled rather than asserted. More about Hipsana →

Sources

  • HHS Office for Civil Rights, settlement with Bryan County Ambulance Authority (October 2024).
  • HHS Office for Civil Rights, settlement with Deer Oaks, a behavioral health provider (July 2025).
  • HHS Office for Civil Rights, settlement with Health Fitness Corporation (March 2025).
  • HHS Office for Civil Rights, Risk Analysis Initiative settlement with a Michigan surgical group ($10,000, January 2025).
  • HHS Office for Civil Rights, HIPAA Audit Program.
  • HHS Office of Inspector General, review of OCR's HIPAA Audit Program (2024).
  • 45 CFR §§ 164.308, 164.400-414, 164.504(e), and 160.404-160.408.
  • 45 CFR § 164.524 (individual right of access) (eCFR, current).
  • Federal Register, HHS civil monetary penalty inflation adjustment, effective January 28, 2026.
  • Federal Register, HIPAA Security Rule NPRM, January 6, 2025.
  • HHS Office for Civil Rights, Right of Access enforcement actions (2022).

Frequently asked questions

Does OCR randomly audit small dental practices?

Rarely. The current audit round, restarted in late 2024, covers about 50 organizations nationwide and is focused on the Security Rule provisions most relevant to hacking and ransomware attacks. The far more common way a small practice ends up in front of OCR is through a patient complaint or a breach the practice itself had to report.

What is the difference between a HIPAA audit and a HIPAA investigation?

An audit is a periodic, documentation-based review OCR initiates to encourage compliance, and historically it has produced no fines on its own. An investigation is OCR's response to a specific event, usually a complaint or a reported breach, and it is the process that leads to settlements and penalties.

How much is a HIPAA fine for a small dental practice?

There is no single number, but recent settlements for one of the most common failures, a missing risk analysis, have ranged from about $10,000 to over $225,000, plus a corrective action plan lasting two to three years. The seven-figure figures you may have read about generally apply to large organizations or the most serious, uncorrected violations.

Is the free HHS risk assessment tool enough?

It is a fair starting point for understanding what a risk analysis involves, but it is not a finished assessment on its own. It gives you the questions, not the answer to which gaps exist in your specific practice. The HIPAA Risk Scorecard checks ten core Security Rule controls that line up with the issues OCR raises most, then follows with a short review. It is a starting point, not a formal risk analysis.

What happens if a breach affects more than 500 patients?

On top of notifying the affected individuals and OCR, you must notify prominent media in the area, and your practice is listed on OCR's public breach portal. For a solo practice, the reputational exposure of that listing can matter as much as any settlement.

Can a dentist lose their license over a HIPAA violation?

Not from OCR directly. OCR enforces HIPAA with civil settlements and corrective action plans, and it has no power over your dental license. Licensure is handled by your state dental board, under state law. A serious privacy violation can draw a state board's attention, and state Attorneys General also have authority to bring their own HIPAA cases. The situations where a dentist has actually lost a license generally came from state action over the underlying conduct, not from a HIPAA fine itself.

Can a HIPAA violation be a crime?

Rarely, and not for ordinary compliance gaps. Criminal HIPAA cases are prosecuted by the Department of Justice and are reserved for knowingly obtaining or disclosing patient information wrongfully, such as selling records or snooping with intent to harm. At the most serious level, involving intent to sell or profit from the data, the law allows fines up to $250,000 and up to ten years in prison. A practice that simply skipped its risk analysis is in civil territory, not criminal.

Are the 2026 HIPAA Security Rule changes already in effect?

No. In January 2025, OCR proposed a major Security Rule update that would, among other things, make encryption and multi-factor authentication mandatory and remove today's addressable flexibility. As of mid-2026 it is still a proposed rule. OCR has not issued a final version and has not confirmed when, or whether, it will. The current Security Rule still governs, and the risk analysis it already requires is what OCR is enforcing right now. If the rule is finalized, practices would get roughly eight months to comply.

Will having a risk analysis stop a fine?

It is not a guarantee, and no document makes a real breach disappear. But OCR weighs your compliance history and good-faith efforts when deciding on a penalty, so a current, honest risk analysis materially changes how an investigation is likely to go.

Not sure where your practice stands?

The free HIPAA Scorecard checks ten core Security Rule controls and scores your practice out of 100. About three minutes, no cost. A starting point, not a full audit.

Check my practice →