BAA HIPAA Compliance: The Agreement That Prevents Breaches
In June 2023, OCR settled with a dental management company for $350,000 after discovering it had allowed a business associate to access protected health
A collection of 29 posts
In June 2023, OCR settled with a dental management company for $350,000 after discovering it had allowed a business associate to access protected health
In 2023, OCR settled with a business associate that failed to ensure its subcontractors had proper safeguards in place for protected health information. The penalty
In 2023, OCR settled with a business associate that failed to ensure its subcontractor had adequate safeguards for protected health information — resulting in a six-figure
In September 2023, OCR settled with a health system for $1.3 million after investigators found the organization had allowed a vendor to access protected
In June 2023, OCR settled with a business associate — a medical records management company — for $75,000 after a breach exposed the protected health information
In 2024, OCR settled with a New England dermatology practice for $300,000 after an investigation revealed it had allowed a business associate to access
In 2023, OCR settled with a business associate — a medical records management company — for $100,000 after an investigation revealed failures to safeguard protected health
In 2023, OCR settled with a healthcare provider for over $100,000 after an investigation revealed that staff routinely sent unencrypted emails containing protected health
In 2024, OCR settled a case with a healthcare provider that had been storing patient records in a cloud-based email platform — without a signed Business
When OCR investigated a small medical practice in 2023 for storing patient records in a consumer Gmail account without a Business Associate Agreement, the practice
In 2024, OCR settled with a medical transcription company for $1.2 million after a breach investigation revealed the business associate had never conducted a
In 2023, OCR settled with a healthcare provider for over $1.25 million after an investigation revealed that protected health information was being shared through
Join healthcare organizations that trust HIPAA Certify for their workforce training and compliance tracking.