Six Risk Assessments Fail to Prevent $2.7 Million HIPAA Settlement

Oregon Health and Science University (OHSU) reached a settlement with OCR earlier in July for $2.7 million. The organization had executed six risk analysis over the course of 10 years, but the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) found that those risk assessments did not constitute a sufficient HIPAA compliance plan. This case should be a clear sign to healthcare professionals that [...]