HIPAA Mental Health Records: Privacy Rules You Must Know
In 2022, OCR settled with a New England dermatology practice for $300,640 after a breach exposed patient records — including sensitive mental health information — that
Office for Civil Rights HIPAA enforcement actions, investigations, and compliance strategies
In 2022, OCR settled with a New England dermatology practice for $300,640 after a breach exposed patient records — including sensitive mental health information — that
In 2023, OCR settled with a health system for $1.3 million after an investigation revealed that employees across multiple departments had unrestricted access to
When OCR announced a $4.8 million settlement with New York-Presbyterian Hospital and Columbia University in 2014, it was one of the first major enforcement
In 2018, OCR settled with Filefax Inc. for $100,000 after the company left medical records — paper records containing protected health information — sitting in an
When OCR investigators arrive at a covered entity's door — whether triggered by a patient complaint or a reported breach — the first thing they
In 2023, OCR settled with a covered entity for $40,000 after a former employee accessed patient records without authorization — months after leaving the organization.
When OCR investigated Anthem Inc. and imposed a record $16 million settlement in 2018, the enforcement action didn't just cite a data breach.
In 2023, a small specialty clinic in the Southeast received a corrective action plan from OCR after a breach investigation revealed that their "policies
In February 2024, OCR settled with a New England dermatology practice for $300,000 after an investigation revealed that workforce members had never completed documented
In 2023, OCR settled with a dental practice in New England for $350,000 after investigators discovered the organization had no written policies governing the
In 2023, OCR settled with a Florida-based health system for $1.2 million after investigators found that the organization lacked a qualified individual overseeing its
In 2023, a dental practice in New England paid $50,000 to settle an OCR investigation after a workforce member posted a patient's
Join healthcare organizations that trust HIPAA Certify for their workforce training and compliance tracking.