Your year-end risk analysis flagged eleven gaps. Nine of them will still be open next December unless each one gets a named owner, a due date, and a line of evidence attached to it. That gap — between knowing about a problem and proving you fixed it — is exactly what a HIPAA corrective action plan closes. This article is for the person who has to write one: the practice owner, the privacy officer, the compliance lead who just inherited a list of findings and no format to track them in. You will get the required elements, the trigger events, a worked example, and the retention rule that decides how long you keep the file.

Two Different Documents Share the Name "Corrective Action Plan"

The first is the one the Office for Civil Rights imposes on you. It is an exhibit attached to a resolution agreement, negotiated after an investigation, and it typically runs one to three years with mandatory reports to HHS. You do not draft it alone, and you do not get to close it on your own schedule.

The second is the one you write yourself — after a risk analysis, a breach investigation, an internal audit, a patient complaint, or a failed vendor review. Nobody outside the practice sees it unless something goes wrong. This is the one most practices need and most practices skip.

Write the internal version as if the external version is coming. The formats are close enough that a well-run internal CAP file is the single most useful thing you can hand an investigator during a document request. It demonstrates that you found the problem before they did and that you acted on it.

What Goes in a HIPAA Corrective Action Plan

A HIPAA corrective action plan documents a specific compliance deficiency, the root cause, the remediation steps, the person accountable, the completion date, and the evidence proving the fix took hold. At minimum, each entry should contain:

  1. Finding ID and date identified — a unique reference you can cite in board minutes and incident logs.
  2. Source of the finding — risk analysis, breach investigation, workforce complaint, audit, vendor assessment, or OCR inquiry.
  3. The deficiency in plain language — what is actually wrong, not the regulatory citation alone.
  4. The applicable HIPAA standard — for example, 45 CFR 164.308(a)(1)(ii)(A) for risk analysis or 164.502(e) for business associate contracts.
  5. Root cause — why the control failed, stated in one or two sentences.
  6. Corrective actions — discrete, verifiable steps, each with an owner by name and title.
  7. Target and actual completion dates — both, so slippage is visible.
  8. Evidence of completion — the artifact you would attach: a signed policy, a training roster, a screenshot of an access review, an executed agreement.
  9. Effectiveness verification — how and when you will confirm the fix is still working.

If a row is missing an owner or a date, it is not a corrective action plan. It is a wish list.

The Five Trigger Events That Should Start a CAP

1. A risk analysis finding you cannot fix the same week

The Security Rule pairs risk analysis with risk management — 164.308(a)(1)(ii)(B) requires you to implement measures sufficient to reduce identified risks to a reasonable level. Your CAP is the paper trail connecting the two. Anything you can fix in an afternoon, fix it and log it. Anything requiring budget, a vendor, or a schedule change goes on the CAP.

2. A breach or near-miss investigation

Every breach investigation produces at least one control failure, even when the breach itself was unavoidable. Notification deadlines and corrective action run on separate clocks: individual notice is due without unreasonable delay and no later than 60 days from discovery, while your remediation timeline is whatever you can defend as reasonable. Document both. Breaches affecting 500 or more individuals appear on the OCR breach portal, and investigators will ask what changed afterward.

3. A right-of-access complaint

If a patient asks for records and your front desk takes 45 days to respond, you have a finding. The access standard gives you 30 days with one 30-day extension on written notice. OCR has pursued access complaints aggressively for years through its Right of Access Initiative, and most of those cases involve small practices with no documented request-tracking process. A CAP entry here looks like: log every request at intake, assign a due date at the moment of receipt, escalate at day 20.

4. A workforce sanction event

Snooping, misdirected faxes, texting PHI to a personal phone. Apply the sanction under your policy — 164.308(a)(1)(ii)(C) requires one — then open a CAP entry addressing the systemic cause. If three people made the same mistake, the problem is your training or your workflow, not your people.

5. A vendor or BAA gap

Vendor inventories almost always surface at least one contractor touching PHI without a signed agreement in the file: the transcription service, the shredding company, the IT contractor with remote access, the answering service. Under 164.502(e) and 164.308(b), that gap is a live violation for as long as it persists, and it is one of the fastest CAP items to close.

When your inventory turns up a missing contract, you can generate a signature-ready Business Associate Agreement through a six-step wizard and export it as PDF or DOCX the same day — a one-time purchase, no subscription. Attach the executed copy to the CAP row as your evidence artifact and the finding closes cleanly.

Write a Root Cause That Is Actually a Cause

"Staff error" is not a root cause. "Employee did not follow policy" is not a root cause either — it is a restatement of the finding.

Useful root causes sound like this: the intake form has no field for the patient's preferred contact method, so staff guess. Termination notices go from the practice manager to payroll but never to IT, so accounts stay live for weeks. The EHR access review is scheduled annually but nobody owns it, so it has not run since the software was implemented.

Test your root cause statement this way: if you fix the thing you named, does the finding become impossible or merely unlikely? If it becomes merely unlikely, dig one level deeper.

Owners, Dates, and Evidence: The Three Columns Read First

Assign owners by name and role, never by department. "IT will address" produces nothing. "Maria Delgado, Practice Manager — due February 14" produces something.

Set target dates that reflect risk, not convenience. A tiering convention most practices can defend:

  • High — active exposure of PHI, missing BAA with a vendor currently handling data, unencrypted device in circulation. Target: 30 days.
  • Medium — policy gaps, incomplete training, overdue access reviews. Target: 90 days.
  • Low — documentation cleanup, redundant controls, process refinements. Target: 180 days or next annual cycle.

The evidence column is where most plans fall apart. Decide the artifact before you start work, because it shapes how you do the work. If the evidence is "training roster with signatures and date," you will run a real session. If you leave the column blank until afterward, you will end up writing "completed" and nothing else — which proves nothing eighteen months later when the person who did it has left.

A Worked Example: Unencrypted Laptop Found During Inventory

Your December asset inventory turns up a laptop assigned to a billing contractor. Full-disk encryption was never enabled. The device has been used to access the practice management system for roughly fourteen months.

  • Finding: CAP-2025-07. Identified December 9, 2025, during annual asset inventory.
  • Standard: 45 CFR 164.312(a)(2)(iv) encryption and decryption; 164.310(d)(1) device and media controls.
  • Root cause: Contractor-owned devices were never added to the IT provisioning checklist, so the encryption step that applies to practice-owned laptops was never triggered.
  • Action 1: Enable full-disk encryption on the device or replace it. Owner: IT vendor lead. Due December 19. Evidence: encryption status report.
  • Action 2: Conduct a breach risk assessment under 164.402 to determine whether notification is required. Owner: privacy officer. Due December 16. Evidence: signed four-factor assessment memo retained regardless of outcome.
  • Action 3: Revise the onboarding checklist to cover contractor devices; require attestation before credentials are issued. Owner: practice manager. Due January 15. Evidence: revised checklist, version-dated.
  • Action 4: Confirm the contractor's BAA addresses device security and safeguards. Owner: privacy officer. Due January 9. Evidence: executed agreement on file.
  • Effectiveness check: Spot-audit five contractor devices in April 2026. Owner: privacy officer.

Notice that the finding produced four actions across three owners, and that only one of them touches the laptop itself. That ratio is normal. A HIPAA corrective action plan that lists one action per finding usually means somebody fixed the symptom and stopped.

What OCR-Imposed CAPs Include — and What to Borrow

The corrective action plans attached to OCR resolution agreements follow a recognizable pattern: revise policies and submit them to HHS for approval, distribute the revised policies to the workforce, train and document the training, conduct or update a Security Rule risk analysis, implement a risk management plan, and report to HHS on a fixed schedule for the monitoring period. You can read the full text of dozens of them on the HHS page for resolution agreements and civil money penalties.

Borrow three habits from those documents. First, they always define who reviews and approves each deliverable. Second, they always set reporting intervals rather than a single end date. Third, they require the entity to report "reportable events" — instances of workforce noncompliance — during the monitoring period, which forces ongoing attention instead of a one-time scramble.

For the technical content of remediation steps, NIST's SP 800-66 Revision 2 maps Security Rule standards to specific safeguards and is the most useful free reference for writing actions that are testable rather than aspirational.

Closing a Finding: The Effectiveness Check Most Practices Skip

Completion and closure are different states. A finding is complete when the actions are done. It is closed when you have verified the control is operating.

Build a 60-to-90-day lag into every closure. Trained the front desk on verbal disclosure limits in January? In April, listen to five interactions or review five request logs. Implemented quarterly access reviews? Confirm the second quarter's review actually ran.

Record the verification result in the same row. "Verified April 14, 2026 — five of five contractor devices encrypted; no exceptions" is a sentence that ends an argument. This is also how you satisfy the evaluation standard at 164.308(a)(8), which requires periodic technical and nontechnical evaluation of your safeguards.

Retention: Six Years, and the Clock May Restart

Section 164.316(b)(2)(i) requires you to retain required documentation for six years from the date of creation or the date it last was in effect, whichever is later. Your CAP, the evidence artifacts, and the policy versions it produced all fall under that rule. Keep the superseded policy versions too — they establish what was in force at the time of an incident.

Store the plan somewhere the privacy officer's successor will find it. A spreadsheet on one person's desktop fails every succession test. A dated file in a shared, access-controlled location, reviewed at a standing quarterly meeting, survives turnover.

Put It on the Calendar Before January Ends

Three recurring items keep a CAP alive: a monthly 20-minute owner check-in on open high-priority rows, a quarterly full review with dates and evidence read aloud, and an annual reconciliation against your current risk analysis. HHS and ONC also maintain a free Security Risk Assessment Tool that produces findings in a format you can feed straight into a CAP.

Also watch the regulatory floor. OCR published a proposed rule in January 2025 that would tighten Security Rule requirements and reduce flexibility around "addressable" implementation specifications. It was not final as of this writing, but practices with a functioning corrective action process will adapt to whatever emerges with far less disruption than practices starting from a blank page.

If your CAP is mostly vendor and documentation gaps, start where the wins are fastest: produce and execute the Business Associate Agreements you are missing, then work through the policy set and risk analysis with a tool that automates the full HIPAA compliance document set. Every closed row with a dated artifact behind it is one fewer thing to explain later.