When Is a Breach Notification Not Required Under HIPAA
In 2023, OCR received over 700 large breach reports from covered entities and business associates — each one triggering federal and state notification obligations, media attention,
Office for Civil Rights HIPAA enforcement actions, investigations, and compliance strategies
In 2023, OCR received over 700 large breach reports from covered entities and business associates — each one triggering federal and state notification obligations, media attention,
In February 2023, OCR settled with Banner Health for $1.25 million after a breach affecting nearly 3 million individuals — partly because the organization'
In 2023, OCR settled with Banner Health for $1.25 million after a breach affecting over 2.81 million individuals — a case that hinged on
Every week, at least one compliance officer or new hire sends me some version of the same question: where can I get HIPAA certification? The
In 2023, OCR settled with a health system for $1.3 million after investigators found the organization had failed to implement basic access controls on
In 2023, OCR settled with a healthcare analytics company for over $1.5 million after the organization shared datasets it believed were de-identified — but which
In 2023, OCR settled with a covered entity for $1.3 million after an investigation revealed the organization had misclassified certain data as non-PHI — and
In 2023, OCR settled with a dental practice for $350,000 after an investigation revealed the organization had been disclosing patient names, treatment records, and
During a 2023 OCR investigation, a mid-sized cardiology practice received a $1.5 million penalty — not because of a sophisticated cyberattack, but because staff routinely
Every year, OCR investigations reveal the same pattern: organizations that misidentify what HIPAA actually requires end up with the most damaging audit findings. One of
In 2023, OCR settled with a dental practice in New England for $50,000 after finding it had no policies implementing the Privacy Rule — despite
When OCR levies a multimillion-dollar penalty against a covered entity for failing to conduct a risk analysis, the enforcement action traces its authority back to
Join healthcare organizations that trust HIPAA Certify for their workforce training and compliance tracking.