On June 18, 2025, U.S. District Judge Matthew Kacsmaryk of the Northern District of Texas (the “District Court”) vacated a 2024 final rule issued by the U.S. Department of Health and Human Services (“HHS”) under the Biden...more
7/1/2025
/ Administrative Procedure Act ,
Biden Administration ,
Data Privacy ,
Department of Health and Human Services (HHS) ,
Enforcement Actions ,
Final Rules ,
Health Insurance Portability and Accountability Act (HIPAA) ,
Judicial Authority ,
Popular ,
Privacy Laws ,
Reproductive Healthcare Issues ,
Trump Administration
In the past several weeks, the U.S. Department of Health and Human Services ("HHS"), Office for Civil Rights ("OCR") has announced settlements with three health care organizations — Comstar, LLC ("Comstar"); Guam Memorial...more
On February 25, 2025, President Trump issued an Executive Order titled “Making America Healthy Again by Empowering Patients with Clear, Accurate, and Actionable Healthcare Pricing Information” (the 2025 Order). This directive...more
On March 6, 2025, the U.S. Department of Health and Human Services (“HHS”) Office for Civil Rights (“OCR”) announced a civil money penalty (“CMP”) of $200,000 against Oregon Health & Science University (“OHSU”) for failing to...more
3/25/2025
/ Civil Monetary Penalty ,
Compliance ,
Department of Health and Human Services (HHS) ,
Enforcement Actions ,
Health Care Providers ,
Health Insurance Portability and Accountability Act (HIPAA) ,
Hospitals ,
Medical Records ,
OCR ,
Patient Access ,
Policies and Procedures
December 2024 was an active month for the U.S. Department of Health and Human Services ("HHS"), Office for Civil Rights ("OCR"). OCR announced (i) a $1.19 million civil monetary penalty ("CMP") against Gulf Coast Pain...more
1/9/2025
/ Civil Monetary Penalty ,
Compliance ,
Data Breach ,
Data Security ,
Department of Health and Human Services (HHS) ,
Enforcement Actions ,
Health Insurance Portability and Accountability Act (HIPAA) ,
HIPAA Privacy Rule ,
HIPAA Security Rule ,
OCR ,
Popular ,
Settlement
On November 1, 2024, the U.S. Department of Health and Human Services (“HHS”), Office for Civil Rights (“OCR”) announced a $90,000 settlement with Bryan County Ambulance Authority (“BCAA”), a provider of emergency medical...more
11/21/2024
/ Corrective Action Plans (CAPs) ,
Cybersecurity ,
Data Breach ,
Department of Health and Human Services (HHS) ,
Electronic Protected Health Information (ePHI) ,
Enforcement Actions ,
Health Care Providers ,
Health Insurance Portability and Accountability Act (HIPAA) ,
HIPAA Security Rule ,
OCR ,
PHI ,
Ransomware ,
Settlement
On October 31, 2024, the U.S. Department of Health and Human Services (“HHS”), Office of Civil Rights (“OCR”) announced a $500,000 settlement with Plastic Surgery Associates of South Dakota (“PSA”) concerning potential...more
11/11/2024
/ Compliance ,
Cybersecurity ,
Data Breach ,
Data Security ,
Department of Health and Human Services (HHS) ,
Electronic Protected Health Information (ePHI) ,
Enforcement Actions ,
Fines ,
Health Care Providers ,
Health Insurance Portability and Accountability Act (HIPAA) ,
HIPAA Violations ,
OCR ,
PHI ,
Settlement