Need a new search?

If you didn't find what you were looking for, try a new search!

Practice Fusion HIPAA FTC Settlement a “Sign of Things to Come” for HIPAA-Beholden EHR Vendors

On June 8th, 2016 the Federal Trade Commission (FTC) announced a settlement with Practice Fusion, Inc. The EHR vendor was charged with illegally disclosing consumers' protected health information (PHI) without providing information about how it would be used, maintained, and protected, in addition to neglecting to obtain their clients' consent. The HIPAA FTC Settlement Practice Fusion is an electronic health records (EHR) platform used by [...]

2023-08-08T10:41:47-04:00June 28th, 2016|

Hackensack Meridian Health Reaches $100,000 OCR Settlement

OCR started the month as they ended last month, by announcing a HIPAA Right of Access settlement. On April 1, 2024, the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) settled with Hackensack Meridian Health for $100,000 to resolve a potential HIPAA violation. The Complaint and the Settlement In May 2020, a complaint was filed against Hackensack Meridian [...]

2024-04-05T15:37:52-04:00April 1st, 2024|

Phoenix Healthcare Reaches OCR Settlement to Resolve Potential Violation

On March 29, 2024, the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) announced it had reached a settlement with Phoenix Healthcare for $35,000. The multi-location nursing care facility agreed to the settlement to resolve a potential HIPAA right of access violation. This marks the 47th enforcement action settled under OCR’s Right of Access Initiative. The Complaint and [...]

2024-03-29T14:38:24-04:00March 29th, 2024|

Ransomware Attack Leads to Another OCR Settlement

On February 21, 2024, Green Ridge Behavioral Health agreed to a settlement with the Department of Health and Human Services (HHS) Office for Civil Rights (OCR). The HHS settlement, resulting from an investigation into a 2019 ransomware attack, requires the behavioral health provider to pay $40,000, implement a corrective action plan, and submit to three years of OCR monitoring. In October 2023, [...]

2024-02-23T10:34:19-05:00February 23rd, 2024|

Montefiore Medical Center Slapped with $4.75 Million HHS Settlement

If the first HHS settlement of 2024 is any indication of what’s to come, it’s going to be an expensive year for violators of HIPAA. On February 6, 2024, Montefiore Medical Center reached a settlement with the HHS over potential HIPAA Security Rule violations. To close the investigation, Montefiore agreed to pay $4.75 million and submit to a corrective action plan. The [...]

2024-04-26T10:02:02-04:00February 6th, 2024|

A Deep Dive into 2023 HIPAA Violation Fines

HIPAA fines are issued for various reasons and are usually the result of a settlement to end an Office for Civil Rights (OCR) investigation. OCR investigates organizations when breaches occur, or there is a complaint by a patient or employee. In 2023, OCR settled thirteen cases with healthcare organizations for potential HIPAA violations. This article covers HIPAA enforcement trends for 2023 and offers advice on how [...]

2024-01-19T11:50:33-05:00January 8th, 2024|

2024 HIPAA Predictions and Emerging Compliance Trends

In healthcare, some things are predictable while others are not. We spoke with top regulatory attorneys, analyzed OCR fines over the last year, and diligently reviewed the HHS site to make predictions about what’s to come for healthcare compliance in 2024. There are a handful of emerging compliance trends for 2024 that are evident. Right of access enforcement will continue to be [...]

2024-01-11T10:35:56-05:00January 5th, 2024|

2023 HIPAA Year-End Wrap-Up: HHS Issued $4 Million in Fines, Breaches Affected 109M Patients

2023 was a banner year for healthcare fines and breaches. The Department of Health and Human Services (HHS) Office for Civil Rights settled thirteen cases with healthcare organizations for potential HIPAA violations. The OCR breach portal also listed 553 large-scale breaches on its site. 2023 OCR Fines: Who and Why In 2023, the HHS OCR settled cases with eight covered entities and [...]

2024-01-08T12:06:58-05:00January 2nd, 2024|

New York Attorney General Settlements Garners $400,000

On December 8, 2023, Healthplex, one of the largest dental administrators in New York state, settled a case with state regulators over a 2021 phishing incident. As a result of the cyberattack, 90,000 patients' information was compromised. The Incident and Settlement In November 2021, an unknown attacker sent a phishing email to an employee of Healthplex. As a result, the hacker gained [...]

2023-12-22T11:31:06-05:00December 22nd, 2023|

Optum Medical Care Settlement Marks OCR’s 46th Right of Access Enforcement Action

On December 15, 2023, the U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR), announced a $160,000 right of access settlement. Since OCR announced its focus on right of access enforcement in 2019, it has settled with 46 healthcare organizations for potential violations of the standard. In a press release announcing the most recent right of access settlement, [...]

2023-12-22T11:31:09-05:00December 18th, 2023|