HIPAA Violation Laws: What Every Covered Entity Must Know
In February 2023, OCR settled with Banner Health for $1.25 million after a breach affected nearly 3 million individuals. The investigation revealed longstanding failures
Content about HIPAA Security Rule safeguards and workforce training.
In February 2023, OCR settled with Banner Health for $1.25 million after a breach affected nearly 3 million individuals. The investigation revealed longstanding failures
Every month, OCR receives complaints about protected health information sent via unsecured text messages — a nurse texting a patient's lab results to a
In February 2023, OCR settled with Banner Health for $1.25 million after a breach affecting over 2.81 million individuals exposed systemic failures in
In January 2024, a registered nurse at a mid-size hospital system was terminated and reported to OCR after accessing the medical records of a coworker&
In 2024, OCR settled with a New England dermatology practice for $300,640 after investigators found that protected health information had been disclosed to a
In March 2024, OCR settled with a small medical practice in California for $100,000 after an investigation revealed that not a single employee had
In February 2024, OCR announced a $4.75 million settlement with Montefiore Medical Center after a former employee stole the protected health information of over
In 2023, a dental practice in New England paid over $50,000 to settle an OCR investigation triggered by a single unencrypted email containing patient
In February 2024, OCR settled with a dental practice for $70,000 after an employee disclosed a patient's treatment information on social media.
When OCR settled with Banner Health for $1.25 million in 2023, the core finding was painfully familiar: the organization had failed to conduct an
In 2023, OCR settled with a healthcare provider for $1.3 million after an investigation revealed the organization had no encryption on portable devices, no
In 2023, OCR settled with a covered entity for $1.25 million — not because of a sophisticated cyberattack, but because the organization lacked a written,
Join healthcare organizations that trust HIPAA Certify for their workforce training and compliance tracking.