Security Safeguards HIPAA: What OCR Expects in 2024
In February 2024, OCR settled with a healthcare system for $4.75 million after investigators found the organization had failed to implement even basic security
Office for Civil Rights HIPAA enforcement actions, investigations, and compliance strategies
In February 2024, OCR settled with a healthcare system for $4.75 million after investigators found the organization had failed to implement even basic security
In 2023, OCR settled with a New England dermatology practice for $300,640 after an unencrypted thumb drive containing the protected health information of over
In 2016, OCR settled with a business associate for $650,000 after a subcontractor experienced a breach affecting over 11,000 patients — and no business
In 2024, OCR settled with a New England dermatology practice for $300,640 after an investigation revealed the organization had no policies implementing the Privacy
In 2023, CMS published over 12.9 billion dollars in physician payment data through the Open Payments database — the public-facing arm of the Sunshine Act.
When OCR announced in late 2023 that the COVID-era telehealth enforcement discretion would not last forever, many healthcare organizations realized they had been operating telemedicine
In 2023, a dermatology practice in Connecticut paid $150,000 to settle an OCR investigation that traced back, in part, to unsecured electronic communications — including
In 2023, a dental practice in Texas paid a $50,000 settlement to OCR after a staff member texted appointment reminders containing diagnostic codes to
In February 2024, OCR settled with a Louisiana medical group for $480,000 after the office failed to provide a patient timely access to her
In 2023, OCR settled with a dental practice in New England for $23,000 after an investigation revealed the organization had disclosed patient appointment information
In June 2023, OCR settled with a dental practice management company for $350,000 after discovering the organization had failed to execute proper agreements with
In 2023, a specialty medical practice in the Southeast received an OCR corrective action after routinely disclosing patient records to a life insurance company without
Join healthcare organizations that trust HIPAA Certify for their workforce training and compliance tracking.