📋 What OCR Looks At
When determining penalties, OCR considers: the nature and extent of the violation, the nature and extent of harm, the organization's compliance history, financial condition, and the organization's cooperation and willingness to correct. Having a current, documented Security Risk Analysis is the single most important mitigating factor.