Quick answer
The Office for Civil Rights does not investigate a location. It investigates the organization. That single fact drives the entire compliance strategy for a multi-location group practice: when something goes wrong at one site, the whole covered entity is on the table. The framework that works is short to state and harder to execute. Centralize the standard, localize the execution, consolidate the proof. That means one organization-wide risk analysis built from real per-site detail, one versioned policy library, one vendor inventory, and one breach plan, with named accountability at every office.
Most multi-location groups grow faster than their compliance does. A practice adds a second office, then a third, then acquires a small group across the state line, and the HIPAA program never quite catches up. Each site runs its own version of compliance, or the group leans on one blanket policy written when there was a single location. Neither holds up.
This post covers what actually scales: the risk analysis, the governance structure, the vendor inventory, the training records, and the breach plan.
Why does one risk analysis have to cover the whole organization?
The foundation of the HIPAA Security Rule is the risk analysis required under 45 CFR 164.308(a)(1)(ii)(A). It is also the single most-failed requirement in the regulation. When OCR ran its Phase 2 audits of covered entities and business associates, only 14 percent of covered entities substantially fulfilled their risk analysis obligation, and only 6 percent adequately handled risk management. That is 86 percent falling short on the analysis and 94 percent falling short on managing what the analysis found.
OCR’s guidance is explicit that the analysis must be accurate, thorough, and organization-wide. It has to account for all of the electronic protected health information the entity holds, regardless of the system, the medium, or the location where it lives. A group cannot satisfy that with a single generic assessment that ignores how each site actually operates, and it cannot satisfy it with a pile of disconnected site reports nobody ever rolls up.
The workable approach is a hybrid. Conduct a per-site asset inventory and data-flow map at each location, because the EHR, the imaging system, the local network, and the vendor mix are rarely identical across offices. Then consolidate those into one enterprise risk register that rates each identified risk, assigns an owner, and tracks remediation to completion. Refresh it at least annually, and again whenever you open a location, add a major system, or onboard a vendor. The output is one defensible analysis an investigator can read end to end, with the site-level detail underneath it. If you want the specifics of what that document has to contain, we covered what OCR actually wants in a risk analysis separately.
What should be identical across sites, and what can vary?
The instinct in a growing group is to let each site handle compliance. That produces ten different programs and ten different gaps. The opposite instinct, a single rigid policy imposed everywhere, ignores that a surgical site and a behavioral health office do not operate the same way. Both fail.
The middle path is deciding, deliberately, what must be identical everywhere and what each site may adapt. Encryption standards, access controls, password and multi-factor authentication requirements, breach escalation, and the core policy set should be identical across the organization. Front-desk workflows, room layouts, and local vendor relationships can vary, as long as they meet the standard. Document both the non-negotiables and the permitted local variation. Then verify adherence centrally rather than trusting that each site is doing it.
Publish one versioned policy library, not a folder of slightly different documents per office. When the rule changes, you update it once and it propagates everywhere. That single source of truth is also what you hand OCR, and it is far more credible than reconciling conflicting versions during an investigation.
Governance follows the same logic. HIPAA requires a designated privacy official under 45 CFR 164.530(a) and a security official under 45 CFR 164.308(a)(2). One person can hold both roles, but in a multi-location group the harder question is reach. A single enterprise officer cannot personally watch every front desk in every city. Name the enterprise officers who own the program and the documentation, then designate a site champion at each location responsible for local execution: training completion, incident reporting, and daily adherence. The enterprise officer sets the standard and holds the evidence. The site champion makes it real on the ground.
Where do group practices usually have gaps?
Vendors. Every vendor that creates, receives, maintains, or transmits PHI on your behalf needs a signed business associate agreement before any PHI is shared, under 45 CFR 164.502(e). In a single practice that is a short list. In a ten-site group it is a sprawling one, and it is usually where the gaps hide.
The failure pattern is predictable. Each location signed its own agreements over the years, some sites use vendors the others do not, and no one holds a complete list. Roll up every vendor relationship across every site into one inventory, confirm a current signed BAA for each, and standardize on group-level agreements where the same vendor serves multiple locations. The goal is a single answer to a simple question: can you produce a signed, current BAA for every vendor touching PHI anywhere in the organization? Most groups cannot, and that is exactly what OCR asks for.
Training records are the second gap. The Privacy Rule requires training your workforce on your policies under 45 CFR 164.530(b) and applying sanctions for violations under 164.530(e). Across many sites the requirement is identical but the logistics are the trap. Assign training by role and location, track completion centrally, and capture an attestation from each staff member. The documentation is half the requirement. An investigator does not want to hear that you train people. They want the records, by name, for the current year, across every site.
Breach response is the third. Under the Breach Notification Rule, individual notice is due without unreasonable delay and no later than 60 calendar days after discovery, per 45 CFR 164.404. For a breach affecting 500 or more individuals, notice to HHS goes contemporaneously with that individual notice under 45 CFR 164.408, and when more than 500 residents of a single State or jurisdiction are involved, 45 CFR 164.406 adds notice to prominent media serving that area. In a multi-location group, a breach at one site is not a site problem. It is an organizational event, and the clock runs the same for everyone. Define who is notified, who leads, how the determination gets made, and how notification happens before anything goes wrong. The first 72 hours after an incident are not the time to discover that three sites have three different ideas of what to do.
Groups that cross state lines inherit one more layer. State privacy statutes like the Texas Data Privacy and Security Act and the California Consumer Privacy Act reach non-PHI data, including marketing lists, website tracking, and consumer information HIPAA does not cover. Map which laws apply where, because the obligations and the enforcers differ.
Why this matters now
OCR’s enforcement posture has sharpened, and it has reached well past health systems. The Risk Analysis Initiative began with an October 2024 settlement involving a county ambulance authority and has continued through 2026 and across a change in administration, which is a durable-priority signal worth reading. In April 2026, OCR announced four ransomware settlements on a single day totaling $1,165,000 and covering more than 427,000 individuals. By June 2026 the agency had reached its 20th ransomware settlement and its 14th action under the Risk Analysis Initiative. Every one of the 2026 settlements we reviewed cited the same core failure: no accurate and thorough risk analysis.
The financial exposure is set annually by inflation adjustment. Effective January 28, 2026, HIPAA civil monetary penalties begin at $145 per violation in the lowest tier and reach an annual cap of $2,190,294 for all violations of an identical provision, under Federal Register document 2026-01688. Settlements almost always carry a corrective action plan running two to three years, which is the part that costs a group the most in staff time.
For a multi-location group, exposure scales with the footprint. More sites mean more systems, more vendors, more staff, and more records, which is more surface area for the gap OCR looks for first. That same scale is what makes a centralized program worth building, because doing it once and doing it well costs far less than a settlement plus years of federal oversight across the organization.
The one move
If a group does nothing else this year, produce one accurate, organization-wide risk analysis built from real per-site detail and consolidated into a single enterprise view, then stand up the governance to keep it current. Everything else, the policies, the BAAs, the training records, the breach plan, hangs off that document and the structure around it.
The groups that struggle are not the ones with bad luck. They are the ones that scaled their locations without scaling their compliance, and assumed ten offices could run on a program built for one. The fix is not more software or a thicker binder. It is a single standard, executed locally, with the proof in one place.
North Privacy Advisors builds organization-wide HIPAA risk analyses and privacy programs for medical groups and multi-site practices. If you want to know where your group actually stands before OCR asks, start with our HIPAA Risk Analysis service.
Last Updated: July 30, 2026