Latest Posts › Data Breach

Share:

Behavioral Health Provider Agrees to Pay $225,000 HIPAA Settlement Following Multiple Data Breaches

On July 7, 2025, the U.S. Department of Health and Human Services (“HHS”), Office for Civil Rights (“OCR”) announced a $225,000 settlement with Deer Oaks – The Behavioral Health Solution (“Deer Oaks”), a provider of...more

HHS OCR Continues Active HIPAA Enforcement with Three New Settlements

In the past several weeks, the U.S. Department of Health and Human Services ("HHS"), Office for Civil Rights ("OCR") has announced settlements with three health care organizations — Comstar, LLC ("Comstar"); Guam Memorial...more

Seeing is Believing: A Civil Money Penalty With Warby Parker Following Cybersecurity Incident

On February 20, 2025, the U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR) announced a $1.5 million civil money penalty (CMP) against Warby Parker, Inc. (WP). WP is a manufacturer and online...more

Two CMPs and One Settlement Close Out 2024 HIPAA Enforcement

December 2024 was an active month for the U.S. Department of Health and Human Services ("HHS"), Office for Civil Rights ("OCR"). OCR announced (i) a $1.19 million civil monetary penalty ("CMP") against Gulf Coast Pain...more

Emergency Medical Service Provider Agrees to Pay a $90,000 HIPAA Settlement Following Ransomware Attack

On November 1, 2024, the U.S. Department of Health and Human Services (“HHS”), Office for Civil Rights (“OCR”) announced a $90,000 settlement with Bryan County Ambulance Authority (“BCAA”), a provider of emergency medical...more

No “Trick”: Plastic Surgery Practice Agrees to Pay a $500,000 HIPAA Settlement Following Ransomware Attack

On October 31, 2024, the U.S. Department of Health and Human Services (“HHS”), Office of Civil Rights (“OCR”) announced a $500,000 settlement with Plastic Surgery Associates of South Dakota (“PSA”) concerning potential...more

Medical Practice Agrees to Pay $250,000 HIPAA Settlement Following Ransomware Attack

In late September 2024, the U.S. Department of Health and Human Services (“HHS”), Office for Civil Rights (“OCR”) announced a settlement with Cascade Eye and Skin Centers, P.C., a health care provider in the state of...more

HHS OCR Issues Its Most Recent HIPAA Annual Report and a Second Ransomware Settlement

On February 14, 2024, the U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR) issued two reports to Congress as required by the Health Information Technology for Economic and Clinical Health...more

New Cybersecurity Guide Released

On February 16, 2024, the HHS Office for Civil Rights (OCR) and the National Institute of Standards and Technology (NIST) published a final version of the cybersecurity resource guide (the “Guide”) with respect to the HIPAA...more

NYC Hospital Agrees to Pay $4.75 Million as Part of a HIPAA Settlement

On February 6, 2024, the HHS Office for Civil Rights (“OCR”) announced a settlement with Montefiore Medical Center (“MMC”) for alleged HIPAA Security Rule violations and MMC agreed to pay $4.75 million and enter into a...more

Two Health Care Developments During the Holiday Season

In December 2023, the U.S. Department of Health and Human Services (“HHS”) Office for Civil Rights (“OCR”) announced a $480,000 settlement with a Louisiana medical group following a phishing incident. In 2021, the medical...more

Business Associate Agrees to $100,000 Settlement Following Cyber Attack

On Halloween, the U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR) announced a $100,000 settlement under the Health Insurance Portability and Accountability Act (HIPAA) with Doctors’...more

Health Care Coding and Billing Entity Pays $75,000 Settlement to Resolve HIPAA Data Breach

The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) announced a settlement on June 28, 2023 of potential violations of the Health Insurance Portability and Accountability Act (HIPAA) Privacy...more

No Snooping Nor Snitching Are the Key Takeaways From the Two Most Recent HIPAA Settlements With Covered Entities

The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) recently announced two settlements with HIPAA-covered entities – one in Washington State and one in New Jersey with settlements of $240,000...more

Two New HIPAA Settlements Announced by HHS OCR; Including a $350,000 Settlement for a Business Associate

Earlier this month, the U.S. Department of Health and Human Services (“HHS”) Office for Civil Rights (“OCR”) announced two (2) different settlements, one with a HIPAA business associate for $350,000 and one with a...more

HHS OCR Publishes 2021 HIPAA Complaint and Breach Reports

The 2021 calendar year reports from HHS OCR describe OCR’s efforts that calendar year and are instructive tools for all parties who need to comply with HIPAA to understand macro-level trends....more

Health Care Cybersecurity Continues To Be Relevant

​October was National Cybersecurity Month. As part of its ongoing focus on HIPAA Security Rule awareness and compliance, the Office for Civil Rights (“OCR”) within the Department of Health and Human Services (“HHS”),...more

Health Insurer Agrees to Pay $5+ Million Settlement Resulting From a Data Breach Affecting More Than Nine Million Individuals and...

In one of the final health care-related actions by the Trump Administration, on January 15, 2021, the United States Department of Health and Human Services (HHS), Office for Civil Rights (OCR) announced that Excellus Health...more

City Health Department Agrees to Pay $202,400 for Alleged HIPAA Violations

On October 30, 2020, the U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR) announced a $202,400 Resolution Agreement and Corrective Action Plan (CAP) with the City of New Haven, Connecticut...more

Health Insurer Agrees to Pay $6.85 Million Settlement Related to HIPAA Data Breach Affecting Over 10 Million Individuals

On September 25, 2020, the Office for Civil Rights (OCR) within the U.S. Department of Health and Human Services (HHS) issued a press release announcing that Premera Blue Cross (Premera) had agreed to pay $6,850,000 and...more

Business Associate Agrees to Pay $2.3 Million to Settle HIPAA Data Breach Affecting Over Six Million People

On September 23, 2020, the Office for Civil Rights (OCR) within the U.S. Department of Health and Human Services (HHS) announced that CHSPSC LLC, (CHSPSC) agreed to pay $2,300,000 and adopt a Corrective Action Plan (CAP) to...more

Orthopedic Clinic Agrees to Pay $1.5 Million to Settle Systemic HIPAA Noncompliance

On September 21, 2020 the Office for Civil Rights (OCR) within the U.S. Department of Health and Human Services (HHS), announced that Athens Orthopedic Clinic PA (AOC) agreed to pay $1,500,000, enter into a Resolution...more

Nationwide Dental Practice Ransomware Incident Underscores Heightened Risk for Medical Providers

More than 400 dental offices across the United States were the victim of a recent ransomware attack that prevented dentists from accessing patient records and patient personal data. ...more

New Comprehensive Report Highlights Impact of Healthcare Data Breaches

IBM Security and the Ponemon Institute recently released their 2019 Cost of Data Breach Report (the “Report”). This is the 14th annual report these groups have published.  ...more

“Insecure” Diagnostic Imaging Company Server Leads to $3 Million HIPAA Settlement

On May 6, 2019, the U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR) announced that Touchstone Medical Imaging (TMI) agreed to pay $3,000,000 to settle alleged HIPAA violations arising out of...more

43 Results
 / 
View per page
Page: of 2

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide