Notice of Privacy Practices Definition: What HIPAA Requires
In 2022, OCR settled with a dental practice in North Carolina for $50,000 — not because of a data breach, but because the practice failed
Office for Civil Rights HIPAA enforcement actions, investigations, and compliance strategies
In 2022, OCR settled with a dental practice in North Carolina for $50,000 — not because of a data breach, but because the practice failed
In 2022, OCR settled with a dental practice in Georgia for $62,500 — not because of a data breach, but because the practice failed to
In 2023, OCR settled with a Florida-based dental practice for $30,000 after an investigation revealed the organization had never implemented formal workforce training — despite
When an OSHA inspector walks into your clinic requesting access to employee medical records, exposure logs, and workplace injury documentation, your compliance team faces a
In 2023, a dental practice in the Southeast received citations from both OSHA and OCR within the same six-month window. The OSHA inspection uncovered improperly
When a healthcare clinic in the Midwest received citations from both OSHA and OCR within the same quarter, leadership realized something that too many organizations
In 2023, OCR settled with a dental practice for $350,000 after an investigation revealed the organization had disclosed patient health information PHI to a
In 2023, a mid-sized hospital system paid $1.3 million to settle with OCR after a researcher published a dataset they believed was "anonymized&
In October 2023, OCR settled with a Louisiana medical group for $480,000 after a phishing attack exposed the protected health information of over 34,
In February 2023, OCR settled with Banner Health for $1.25 million after a breach affecting nearly 3 million individuals exposed catastrophic failures in risk
In 2023, OCR settled with a health system that had been using an outdated authorization form for nearly four years — one that failed to include
In February 2024, OCR announced a $4.75 million settlement with a nonprofit health system that failed to conduct an enterprise-wide risk analysis — leaving the
Join healthcare organizations that trust HIPAA Certify for their workforce training and compliance tracking.