OCR closed 21 enforcement actions in 2025 — most began with a breach report or a complaint, not an audit. Get ahead of the letter

Frameworks · HIPAA Security Rule

OCR doesn't grade
good intentions.

If your business touches patient information — as a clinic, a health-tech company, a billing shop, or their IT provider — federal law says you must protect it, and the government fines businesses that can't prove they do. One investigation letter can cost a small practice six figures. We make that letter a non-event: the Cyber Tackle Box™ platform holds your risk review, policies, staff training, and proof — and if you'd rather not touch any of it, Lionfish & partner consultants can run the program for you.

Covered EntitiesBusiness AssociatesMSPs serving healthcareSecurity Rule + NPRM-ready

Technical evaluator? Skip the pitch — jump to the deep dive ↓

For the technical reader — the deep dive
  • Scope: the Security Rule, 45 CFR Part 164 Subpart C, for ePHI — covered entities and business associates alike (BAs have direct OCR liability).
  • The keystone artifact is the §164.308(a)(1) security risk analysis; workforce training is §164.308(a)(5); both are recurring, not one-time.
  • Breach notification: 60 days to individuals; 500+ record breaches reported to OCR and investigated.
  • Penalties (2026-adjusted): four culpability tiers from ~$145 to $72K+ per violation, annual cap $2,190,294 per violation category.
  • The proposed Security Rule update (mandatory MFA, encryption at rest/in transit, asset inventories) has slipped to ~2027 — current-rule enforcement has not.
  • In the Tackle Box: risk analysis workflow, policy set, per-employee training records, BAA tracking, and breach-response playbooks.

Want to go deeper than a web page? Book a call — you'll be talking to a practitioner, not a salesperson.

The numbers behind every OCR settlement

$00K×10
average cost of a healthcare data breach — $7.42M, the highest of any industry (IBM 2025)
$0M÷100
maximum annual HIPAA penalty per violation category — $2,190,294 (2026-adjusted)
0
OCR enforcement actions closed in 2025 — the second-highest year on record
0 days
average time to identify and contain a healthcare breach

Sources: IBM Cost of a Data Breach 2025; HHS/OCR enforcement releases; HIPAA Journal penalty tables. The proposed Security Rule update (mandatory MFA and encryption) is delayed to 2027 — enforcement of the current rule is not.

Who this is for

Covered entities — and the business associates OCR is now naming

HIPAA isn't just for hospitals. OCR settles with billing companies, IT vendors, and software firms — anyone who touches ePHI under a BAA.

  • Independent practices and clinics — medical, dental, behavioral health, imaging — where the "compliance officer" is the practice manager with a day job.
  • Health tech and digital health companies whose covered-entity customers demand a signed BAA plus proof of a real security risk analysis before contracting.
  • MSPs and IT vendors serving healthcare — you're a business associate whether you signed up for it or not, and your clients' OCR risk is your OCR risk.

Sound familiar?

The pain we hear on every first call

  • !The risk analysis you don't have. Inadequate risk analysis is the failure OCR cites in the overwhelming majority of Security Rule enforcement — and a template PDF doesn't survive an investigator.
  • !Training that exists on paper. The Security Rule requires workforce training. "We showed a video once" is how five-figure settlements start.
  • !No certification, no finish line. There is no HIPAA certificate — just your documentation on the day the letter arrives. Ambiguity paralyzes small teams.

The platform

How the Cyber Tackle Box™ runs your HIPAA program

One platform holds the risk analysis, policies, training records, and evidence — the exact artifact set OCR asks for in its first data request.

Policy Templates

Contingency plans, sanction policy, access management, breach response — the full Security Rule document set, pre-built and tailored to your practice or product.

Risk Analysis, For Real

A control-by-control security risk analysis with findings, likelihood, and impact — the OCR-defensible artifact, refreshed annually instead of rebuilt in a panic.

Remediation & POA&Ms

Findings become assigned, dated remediation items driven to closure — evidence of a working program, not a binder.

Evidence & BAA Tracking

Business associate agreements, training records, and control evidence in one timestamped system of record.

Playbooks

Step-by-step breach response and incident playbooks — because the 60-day breach-notification clock starts whether you're ready or not.

Workforce Training Included

The training the rule requires, delivered so people actually finish it — 52 modules including our music-based series, tracked to the individual employee.

Software, services, or both

Two ways to work with Lionfish

The Cyber Tackle Box™ is a product you can run yourself. Our consulting team is a service you can add. Take either — or both. They're priced separately, and we'll tell you straight which one you actually need.

The platform — Cyber Tackle Box™

Software you run yourself: framework-mapped controls, policy templates, evidence, POA&Ms, and workforce training in one system of record. Your team (or your MSP) drives; the platform keeps everything organized and audit-ready.

Book a platform demo

The services — Lionfish & partner consultants

Add Lionfish & partner consultants — led by the team that trains certified CMMC assessors, backed by our vetted Trusted Partner Network — to run the gap assessment, drive remediation, and prepare you for the audit, by, with, and through your team, inside the same platform.

Book a readiness call

For MSPs & partners

Multi-tenant by design: run every client's compliance program from one console and add a services line without adding headcount. White-glove onboarding for your first clients.

Partner with us

Straight answers

HIPAA questions we answer every week

What are the actual HIPAA penalties in 2026?

Civil penalties are tiered by culpability, running from about $145 per violation to over $72,000 per violation, with an annual cap of $2,190,294 per violation category at the highest tier. Most OCR settlements land in the five-to-mid-six figures — an existential number for a small practice or MSP.

Is there a HIPAA certification?

No. HIPAA has no official certification — compliance is demonstrated through your documentation: a current security risk analysis, written policies, workforce training records, BAAs, and evidence your safeguards operate. That's exactly the artifact set the Cyber Tackle Box maintains, so an OCR inquiry is a document export rather than a scramble.

What's happening with the new HIPAA Security Rule?

HHS proposed a major Security Rule update in January 2025 — mandatory MFA, encryption of ePHI at rest and in transit, written asset inventories, and annual audits — but final action has slipped to 2027 and the proposal may be narrowed. Our advice: don't buy panic, but don't wait either. Everything in the proposal is already best practice, and enforcement of the current rule is accelerating right now.

We're an MSP with healthcare clients — where do we start?

You're a business associate, which means direct OCR liability plus contractual exposure to every client. The Cyber Tackle Box is multi-tenant: run your own HIPAA program and your clients' programs from one console, and turn compliance from a liability into a billable service line. We'll show you the MSP model on a demo.

Get in touch

Get HIPAA off your worry list

Tell us whether you're a provider, a business associate, or an MSP with healthcare clients. You'll get a straight assessment of your exposure and a scoped plan within one business day.

  • 1We reply within one business day — usually faster.
  • 2A 30-minute call with someone who can actually answer your questions.
  • 3A straight recommendation — even if it's that you don't need us yet.

Prefer to skip the form? Book a time directly or call 1-877-732-6772.

Book a Free Call