Business Associate HIPAA Agreement: What Must Be Included
In September 2023, OCR settled with a health system for $1.3 million after investigators found the organization had allowed a vendor to access protected
Content about HIPAA Privacy Rule requirements and training.
In September 2023, OCR settled with a health system for $1.3 million after investigators found the organization had allowed a vendor to access protected
In 2024, OCR settled with a New England dermatology practice for $300,000 after an investigation revealed it had allowed a business associate to access
In 2023, OCR settled with a business associate — a medical records management company — for $100,000 after an investigation revealed failures to safeguard protected health
Every month, patients contact OCR after discovering a hospital shared their medical records without authorization, a business associate lost a laptop containing thousands of patient
In February 2023, OCR settled with Banner Health for $1.25 million after a breach affecting nearly 3 million individuals exposed systemic failures across multiple
In 2023, OCR settled with a dental practice for $350,000 after an investigation revealed the organization had disclosed patient names, treatment records, and Social
In 2023, OCR settled with a solo dental practice in New England for $30,000—not because of a massive data breach, but because the
In February 2024, OCR announced a $4.75 million settlement with Montefiore Medical Center after a workforce member stole protected health information (PHI) of over
In February 2024, OCR settled with a Louisiana medical group for $480,000 after an investigation revealed — among other failures — that the organization had never
In February 2024, OCR settled with a Louisiana medical group for $480,000 after investigators found the organization had failed to implement even the most
In February 2024, OCR announced a $4.75 million settlement with Montefiore Medical Center after a former employee stole the protected health information of over
In December 2022, OCR issued a bulletin that sent shockwaves through the healthcare industry. The agency confirmed that common website tracking technologies — pixels, session replay
Join healthcare organizations that trust HIPAA Certify for their workforce training and compliance tracking.