Your risk analysis came back in September with 41 findings. It's December 29. How many are closed, and can you prove the date each one closed on? If you can't answer that in under five minutes, you don't have a HIPAA remediation plan — you have a list of problems you've now documented that you knew about. That distinction is the entire ballgame in an OCR investigation.

This article is for the person who owns that list: the practice owner, the privacy officer, the compliance lead, the IT director who inherited HIPAA because nobody else would. It covers what belongs in the plan, who signs off on each line, what "closed" looks like in a file folder, and how to run the thing on a quarterly cadence without burning a full-time headcount.

What a HIPAA Remediation Plan Is and Where It Lives in the Rule

A HIPAA remediation plan is the written, dated record of how your organization reduces the risks identified in your security risk analysis to a reasonable and appropriate level. It names each gap, assigns an owner, sets a target date, defines the fix, and captures the evidence that the fix happened.

The obligation is not invented by consultants. The Security Rule's administrative safeguards standard requires both a risk analysis at 45 CFR 164.308(a)(1)(ii)(A) and risk management at 164.308(a)(1)(ii)(B) — "implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level." The risk analysis identifies. The remediation plan is how you satisfy the second half.

HHS has been consistent that these are two separate requirements. Its guidance on risk analysis treats the assessment as the input to an ongoing risk management process, not a deliverable that ends when the PDF is filed.

Risk analysis vs. remediation plan vs. corrective action plan

  • Risk analysis — you identify threats, vulnerabilities, likelihood, and impact across everywhere ePHI lives. Required, ongoing.
  • Remediation plan — you decide what to do about each finding, who does it, and by when. Voluntary in format, mandatory in substance.
  • Corrective action plan (CAP) — what OCR imposes on you through a resolution agreement after an investigation. Terms are negotiated with the government, monitored for years, and expensive.

You write the second one so you never negotiate the third one.

The Six Fields Every Remediation Item Needs

Keep the structure boring. A spreadsheet with six columns beats a 60-page narrative nobody updates.

  1. Finding ID and description. Tie it back to the specific risk analysis line item. "RA-2025-014: Three workstations in the billing suite auto-lock at 30 minutes; policy requires 10."
  2. Rule citation. Which standard or implementation specification does this touch? 164.312(a)(2)(iii) for that example. This forces precision and helps at renewal time.
  3. Risk rating. High, moderate, or low, derived from likelihood and impact — not from how annoying the fix is.
  4. Owner by name. Not "IT." Not "the practice." A person who can be asked on a Tuesday.
  5. Target completion date. A calendar date. "Q2" is not a date.
  6. Evidence of closure. The artifact you will point to: a screenshot, a signed policy, a ticket number, a training roster, a countersigned BAA.

Add a seventh column if you want to survive an audit gracefully: interim mitigation. If a fix takes six months, what reduces exposure this week?

Ranking Findings So You Fix the Right Things First

Most practices come out of a risk analysis with 30 to 60 findings. You cannot do them all in January, and pretending otherwise produces a plan that fails in week three.

A severity scale you can defend

NIST's risk assessment methodology in SP 800-66 Revision 2, published in February 2024 specifically to help HIPAA-regulated entities implement the Security Rule, gives you a defensible structure: rate likelihood, rate impact, combine into a risk level. You do not need a formal quantitative model. You need consistency and a written rationale.

Practically, sort into three buckets:

  • High — could lead to a reportable breach of many records, or represents a missing required implementation specification. Unencrypted laptops. No BAA with a vendor that touches ePHI. Terminated employees with live logins.
  • Moderate — a control exists but is weak or inconsistently applied. Audit logs collected but never reviewed. Policies not updated since 2019.
  • Low — documentation gaps, naming inconsistencies, training refreshers.

Worked example: a 12-provider multispecialty group

Three findings from an October assessment:

Finding A: The transcription vendor has been receiving dictation files for 14 months with no executed business associate agreement. Rating: high. Owner: practice administrator. Target: 21 days. Evidence: countersigned BAA, PDF, filed with vendor record. Interim mitigation: none available short of suspending the service — so it moves to the top of the queue. If you're closing gaps like this one, a six-step business associate agreement generator produces a signature-ready document in an afternoon rather than waiting three weeks on outside counsel.

Finding B: No documented process for reviewing system access logs. Rating: moderate. Owner: IT manager. Target: 90 days. Evidence: written log review procedure, plus three months of signed monthly review sheets. Interim mitigation: manual weekly export reviewed by the IT manager starting immediately.

Finding C: Sanction policy exists but staff acknowledgments predate the 2023 revision. Rating: low. Owner: HR lead. Target: 120 days, bundled with annual training. Evidence: re-acknowledgment roster with dates.

Three findings, three ratings, three owners, three dates, three named artifacts. Replicate that 40 times and you have a plan.

Who Owns What: Assigning Roles Without Creating a Committee

The Security Rule requires a designated security official. That person owns the plan itself — the document, the cadence, the reporting. They do not own every line.

  • Security official / privacy officer: maintains the register, chairs the quarterly review, escalates overdue items, signs the closure attestation.
  • Practice administrator / owner: approves budget and accepts residual risk in writing when a fix is deferred.
  • IT (internal or MSP): owns technical safeguard items and produces the technical evidence.
  • HR: owns workforce clearance, termination procedures, sanctions, training completion.
  • Front office supervisor: owns physical safeguards and workflow items — screen positioning, sign-in sheets, fax cover practices, visitor access.

If your IT is outsourced, get remediation items into the MSP's ticketing system with your finding IDs in the subject line. Their tickets become your evidence.

The Timeline: What Reasonable Looks Like

HIPAA sets no deadline for remediation. That silence is not permission to move slowly — it means you set the deadlines and are judged against them. A defensible default:

  • 0–30 days: missing BAAs, active credentials for departed workforce members, unencrypted portable devices, anything with active exposure.
  • 31–90 days: policy updates, access review procedures, contingency plan testing, encryption rollouts on managed endpoints.
  • 91–180 days: logging and monitoring maturity, vendor risk reassessment, tabletop incident response exercise.
  • 181–365 days: capital items — network segmentation, replacing end-of-life systems, facility changes.

Note what runs on separate clocks and cannot be folded into remediation timing: breach notification to affected individuals within 60 days of discovery, and patient access requests within 30 days. Those deadlines are statutory. Your remediation dates are self-imposed but binding on you once written.

Evidence: What "Closed" Actually Looks Like in the File

An investigator will not accept "we fixed it." Each closed item needs an artifact with a date on it.

  • Encryption enabled → management console report showing device names and encryption status, exported and dated.
  • Policy revised → the signed policy with a version number and effective date, plus the acknowledgment roster.
  • Training delivered → completion report listing every workforce member, with dates and score or attestation.
  • BAA executed → the countersigned agreement, both signature dates visible.
  • Access removed → the offboarding checklist with the deactivation timestamp, or the ticket showing it.
  • Log review implemented → the first three completed review records, not just the procedure.

Store evidence alongside the register, not in six different inboxes. When the request letter arrives, you have days — not weeks — to assemble a response.

"Addressable" Does Not Mean Optional

This is the single most common misreading in small-practice compliance files. When an implementation specification is addressable, you must assess whether it is reasonable and appropriate for your environment. If you implement it, do so. If you don't, you must document why, and implement an equivalent alternative measure if one is reasonable.

"We decided not to encrypt" with no written analysis is a finding. "We evaluated full-disk encryption for the three legacy imaging workstations, determined vendor support constraints made it infeasible, and instead isolated those systems on a segmented VLAN with restricted physical access, reassessed annually" is a defensible decision. Your remediation plan should carry these determinations as closed items with the rationale attached.

Worth watching: OCR published a proposed rule in January 2025 that would significantly revise the Security Rule, including removing the required/addressable distinction and mandating specific technical controls. It had not been finalized as of this writing. Build your plan on the current rule, but don't design around the assumption that addressable stays flexible forever.

Running the Plan: A Quarterly Cadence That Survives Contact With a Busy Clinic

Set a recurring 60-minute meeting on the same week each quarter. Agenda, in order:

  1. Items closed since last review, with evidence confirmed — not just reported.
  2. Items overdue, with a new date and a written reason for the slip.
  3. New findings since last review: from incidents, near misses, new vendors, new systems, new locations.
  4. Residual risk acceptances requiring owner sign-off.
  5. Next quarter's targets.

Minutes go in the compliance file. Ten years of retention applies to required documentation under the Security Rule, so treat the minutes as records, not notes.

New findings arrive constantly. Every new EHR module, telehealth platform, billing service, or AI scribe is a scope change that generates remediation work. Reviewing the OCR breach portal once a quarter is a cheap way to see which failure modes are actually hitting practices your size — hacking of network servers and email compromise dominate the list, which should shape your priorities more than any generic checklist.

Five Mistakes That Turn a Remediation Plan Into Evidence Against You

  • Documenting the finding, never the fix. A three-year-old risk analysis with no remediation record establishes that you knew. Willful neglect penalties start there.
  • Assigning ownership to a department. Departments don't get held accountable in a meeting. People do.
  • Rolling target dates forward silently. Move the date and write why. Unexplained drift reads as indifference.
  • Skipping the vendor layer. Your remediation plan should include verifying that business associates have their own safeguards, not just a signed BAA in a folder.
  • Treating the plan as the security official's private file. Ownership needs to see it. Budget decisions are risk decisions.

Building the HIPAA Remediation Plan When You Don't Have a Current Risk Analysis

If your last assessment is older than 18 months, or if it was a vendor questionnaire rather than a real analysis of where ePHI lives, start there. You cannot remediate findings you haven't produced. The SRA Tool from HHS and ONC is free and adequate for small practices willing to invest the hours.

If the hours aren't there — and for most practices under 50 employees they aren't — automating the paperwork is the practical path. A platform that generates your risk analysis, policies, and the full HIPAA document set gives you the findings register, the policy library, and the structure your HIPAA remediation plan hangs on, so your team spends its time closing gaps instead of formatting documents. No product makes you compliant and no vendor issues a government-recognized certification — but the documentation burden is real, and it's the part worth automating.

Pick a date in January. Open your risk analysis. Put six columns in a spreadsheet and fill in the first ten rows before you close it. A HIPAA remediation plan that exists and moves slowly beats a perfect one that never gets written — and by the time someone asks for it, writing it is no longer an option.