News & Analysis as of

Data Breach Settlement Agreements Enforcement Actions

Saul Ewing LLP

HHS OCR Continues Active HIPAA Enforcement with Three New Settlements

Saul Ewing LLP on

In the past several weeks, the U.S. Department of Health and Human Services ("HHS"), Office for Civil Rights ("OCR") has announced settlements with three health care organizations — Comstar, LLC ("Comstar"); Guam Memorial...more

Health Care Compliance Association (HCCA)

From $5,000 to $800,000: Days Apart, OCR Security Settlements Show Puzzling Math

A single incident that may have started as a personal vendetta or an extortion threat seven years ago has cost a Florida health care system $800,000, and comes on the heels of an unrelated breach suffered by a different...more

Ogletree, Deakins, Nash, Smoak & Stewart,...

2025 Enforcement Trends: Risk Analysis Failures at the Center of HHS’s Multimillion-Dollar HIPAA Penalties

In the first five months of 2025, the U.S. Department of Health and Human Services’ (HHS) Office for Civil Rights (OCR) announced it had entered into ten Health Insurance Portability and Accountability Act (HIPAA) resolution...more

Wyrick Robbins Yates & Ponton LLP

Buyers Beware: the FTC’s Case Against CafePress Highlights Privacy and Data Security Risks in Corporate Transactions

Last week the Federal Trade Commission announced a privacy and data security enforcement action against the online retail platform CafePress. The allegations in the FTC’s complaint read like a list of worst practices,...more

Polsinelli

When the Feds Find Out! Lack of Data Security Leads to Novel and Hefty Settlements

Polsinelli on

The Federal Government continues ramping up enforcement of data security requirements by deploying significant new enforcement theories and tools in support of cyber and data security controls required by federal law....more

Bilzin Sumberg

Recent Settlements and Penalties Show Perils of Data Breaches

Bilzin Sumberg on

Two major U.S. financial institutions, Morgan Stanley and Capital One, recently agreed to resolve separate class action lawsuits by paying, in the aggregate, hundreds of millions of dollars in compensation for massive data...more

Robinson+Cole Data Privacy + Security Insider

NYDFS Settles with National Securities Corp. for $3M for Violations of DFS Cybersecurity Regulations

The New York Department of Financial Services (NYDFS) has settled alleged violations of the Department’s strict cybersecurity regulations with National Securities Corp. (NSC) for $3 million, over four separate cybersecurity...more

Robinson+Cole Data Privacy + Security Insider

Home Depot Settles Data Breach Multi-state Enforcement Action for $17.5 Million

Home Depot has agreed to settle a multi-state enforcement action by 46 U.S. states and Washington, D.C. arising from the data breach that occurred in 2014. Home Depot has agreed to pay $17.5 million to put the enforcement...more

Robinson+Cole Data Privacy + Security Insider

Athens Orthopedic Settles with OCR for $1.5M for Data Breach

The U.S. Department of Health and Human Services’ Office for Civil Rights (OCR) has announced that it has settled potential violations of HIPAA with Athens Orthopedic Clinic PA (Athens) for $1.5 million, following an...more

Robinson+Cole Data Privacy + Security Insider

Capital One Settles with Bank Regulator for $80M for Data Breach

The U.S. Office of the Comptroller of the Currency (OCC) announced this week that it has entered into a Consent Order and fined Capital One $80 million for the data breach the company experienced last year....more

Robinson+Cole Data Privacy + Security Insider

Size Doesn’t Matter for OCR Enforcement Actions

Small health care organizations may think they are under the radar of the Office for Civil Rights (OCR), but a settlement the OCR agreed to last week should disabuse small health care providers of that notion....more

Sheppard Mullin Richter & Hampton LLP

2019 Year in Review: Notable Changes in Law, Policy, and Enforcement of HIPAA

According to a December 20, 2019 Report by HIPAA Journal, nearly 39 million health care data breaches had been reported to the U.S. Department of Health and Human Services (“DHHS”), Office of Civil Rights (“OCR”) by the end...more

Shook, Hardy & Bacon L.L.P.

Privacy and Data Security Alert | December 2019

SDNY Rejects Standing under “Increased Risk” Theory Where Data Not Targeted or Stolen - The Southern District of New York rejected a settlement that would have resolved a class action based on the unauthorized (and...more

Orrick, Herrington & Sutcliffe LLP

Recent FTC Cybersecurity Settlements Highlight Benefits and Risks of Settling vs. Litigating

Amidst mounting pressure to pursue cybersecurity more aggressively, the Federal Trade Commission (“FTC”), the federal government’s most active enforcer in the space, has recently imposed increasingly stringent cybersecurity...more

McDermott Will & Emery

Corporate Law & Governance Update - July 2019

McDermott Will & Emery on

IMPACT OF EQUIFAX, FACEBOOK SETTLEMENTS - Health care industry boards should give close attention to the governance implications of recent privacy settlements entered into by Equifax and Facebook. Their unique facts...more

Davis Wright Tremaine LLP

Significant FTC Fines Highlight Evolution in Privacy Enforcement Landscape

Last week produced a spate of interesting and instructive privacy and data security enforcement activity. ...more

Barnea Jaffa Lande & Co.

When the Privacy Watchdogs Bare Their Teeth

July 2019 brought an escalation in the enforcement of privacy infringements by companies around the world. The trend began with a press release published on July 8, 2019, of a fine in the approximate amount of GBP 183 million...more

Ballard Spahr LLP

Equifax Reaches Historic $575 Million Settlement Agreement Arising from 2017 Data Breach

Ballard Spahr LLP on

Equifax has agreed to pay $575 million to settle consumer as well as state and federal regulatory claims for its 2017 data breach. This is the largest data breach settlement to date. ...more

Ballard Spahr LLP

OCR Announces $3 Million HIPAA Enforcement Settlement for Breach of 300,000 Patients’ PHI

Ballard Spahr LLP on

On May 6, 2019, the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) announced an agreement  with Touchstone Medical Imaging, LLC (Touchstone)...more

Carlton Fields

2018 Was A Record Year in HIPAA Enforcement

Carlton Fields on

The Office for Civil Rights (OCR) at the U.S. Department of Health and Human Services recently announced that 2018 was a significant year in Health Insurance Portability and Accountability Act (HIPAA) enforcement activity. ...more

Ballard Spahr LLP

OCR Closes the Book on 2018 With $3 Million HIPAA Settlement

Ballard Spahr LLP on

On February 7, 2019, the Office of Civil Rights (OCR) of the U.S. Department of Health and Human Services published the resolution agreement for its final HIPAA settlement of 2018. ...more

Fenwick & West LLP

Deregulation is the New Buzzword in Washington — Except in the Tech Industry

Fenwick & West LLP on

The past year has been a volatile one, from trade wars to the government shutdown to a stock market dive. One constant that U.S. businesses have become accustomed to, however, is deregulation across a wide variety of...more

Bricker Graydon LLP

Failure to terminate access of departing employee leads to HIPAA penalty

Bricker Graydon LLP on

A critical access hospital in Colorado will pay $114,000 in a settlement with the Office of Civil Rights (OCR) stemming from the failure to terminate a former employee’s access to a hospital database containing protected...more

Burr & Forman

Anthem Will Pay Record $16 Million To Settle Health Care Data Breach

Burr & Forman on

Anthem, Inc., the country’s second largest insurer has agreed to pay $16 million to the U.S. Department of Health and Human Services, Office for Civil Rights (“OCR”) and take corrective action to settle potential violations...more

Robinson+Cole Data Privacy + Security Insider

Anthem Settles with OCR for $16M for 2015 Data Breach

The Department of Health and Human Services Office for Civil Rights (OCR) announced this week that it has settled the largest health care data breach for the largest enforcement fine in history....more

30 Results
 / 
View per page
Page: of 2

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide