On June 18, 2025, U.S. District Judge Matthew Kacsmaryk of the Northern District of Texas (the “District Court”) vacated a 2024 final rule issued by the U.S. Department of Health and Human Services (“HHS”) under the Biden...more
7/1/2025
/ Administrative Procedure Act ,
Biden Administration ,
Data Privacy ,
Department of Health and Human Services (HHS) ,
Enforcement Actions ,
Final Rules ,
Health Insurance Portability and Accountability Act (HIPAA) ,
Judicial Authority ,
Popular ,
Privacy Laws ,
Reproductive Healthcare Issues ,
Trump Administration
On March 6, 2025, the U.S. Department of Health and Human Services (“HHS”) Office for Civil Rights (“OCR”) announced a civil money penalty (“CMP”) of $200,000 against Oregon Health & Science University (“OHSU”) for failing to...more
3/25/2025
/ Civil Monetary Penalty ,
Compliance ,
Department of Health and Human Services (HHS) ,
Enforcement Actions ,
Health Care Providers ,
Health Insurance Portability and Accountability Act (HIPAA) ,
Hospitals ,
Medical Records ,
OCR ,
Patient Access ,
Policies and Procedures
December 2024 was an active month for the U.S. Department of Health and Human Services ("HHS"), Office for Civil Rights ("OCR"). OCR announced (i) a $1.19 million civil monetary penalty ("CMP") against Gulf Coast Pain...more
1/9/2025
/ Civil Monetary Penalty ,
Compliance ,
Data Breach ,
Data Security ,
Department of Health and Human Services (HHS) ,
Enforcement Actions ,
Health Insurance Portability and Accountability Act (HIPAA) ,
HIPAA Privacy Rule ,
HIPAA Security Rule ,
OCR ,
Popular ,
Settlement
On November 1, 2024, the U.S. Department of Health and Human Services (“HHS”), Office for Civil Rights (“OCR”) announced a $90,000 settlement with Bryan County Ambulance Authority (“BCAA”), a provider of emergency medical...more
11/21/2024
/ Corrective Action Plans (CAPs) ,
Cybersecurity ,
Data Breach ,
Department of Health and Human Services (HHS) ,
Electronic Protected Health Information (ePHI) ,
Enforcement Actions ,
Health Care Providers ,
Health Insurance Portability and Accountability Act (HIPAA) ,
HIPAA Security Rule ,
OCR ,
PHI ,
Ransomware ,
Settlement
On October 31, 2024, the U.S. Department of Health and Human Services (“HHS”), Office of Civil Rights (“OCR”) announced a $500,000 settlement with Plastic Surgery Associates of South Dakota (“PSA”) concerning potential...more
11/11/2024
/ Compliance ,
Cybersecurity ,
Data Breach ,
Data Security ,
Department of Health and Human Services (HHS) ,
Electronic Protected Health Information (ePHI) ,
Enforcement Actions ,
Fines ,
Health Care Providers ,
Health Insurance Portability and Accountability Act (HIPAA) ,
HIPAA Violations ,
OCR ,
PHI ,
Settlement