Who Can Have Access to a Patient's PHI Under HIPAA
In 2023, OCR settled with a medical practice for $50,000 after an unauthorized employee accessed patient records with no treatment, payment, or operational justification.
HIPAA requirements and training for business associates and third-party service providers
In 2023, OCR settled with a medical practice for $50,000 after an unauthorized employee accessed patient records with no treatment, payment, or operational justification.
In 2023, OCR settled with a dental practice in New England for $50,000 after finding it had no policies implementing the Privacy Rule — despite
When OCR settled with Anthem Inc. for $16 million in 2018 — the largest HIPAA settlement in history at that time — the enforcement action didn'
In 2023, OCR settled with a business associate that failed to ensure its subcontractors had proper safeguards in place for protected health information. The penalty
In September 2023, OCR settled with a health system for $1.3 million after investigators found the organization had allowed a vendor to access protected
In June 2023, OCR settled with a business associate — a medical records management company — for $75,000 after a breach exposed the protected health information
In 2023, a mid-size health plan received a corrective action from OCR after an investigation revealed that staff responsible for processing electronic claims had never
At least once a month, a compliance officer asks me the same question: "Where do we get our official HHS HIPAA certification?" The
In February 2024, OCR announced a $4.75 million settlement with a healthcare system that failed to conduct an enterprise-wide risk analysis — a fundamental gap
In 2023, OCR settled with a telehealth platform for $1.25 million after an investigation revealed the company's software transmitted protected health information
In February 2024, OCR announced a $4.75 million settlement with Montefiore Medical Center after a former employee stole the protected health information of over
In February 2024, OCR settled with a New England dermatology practice for $300,000 after determining the organization had disclosed protected health information to a
Join healthcare organizations that trust HIPAA Certify for their workforce training and compliance tracking.