Compliant Email: HIPAA Rules for Sending PHI Securely
In 2023, OCR settled with a healthcare provider for over $100,000 after an investigation revealed that staff routinely sent unencrypted emails containing protected health
A collection of 25 posts
In 2023, OCR settled with a healthcare provider for over $100,000 after an investigation revealed that staff routinely sent unencrypted emails containing protected health
In 2024, OCR settled a case with a healthcare provider that had been storing patient records in a cloud-based email platform — without a signed Business
When OCR investigated a small medical practice in 2023 for storing patient records in a consumer Gmail account without a Business Associate Agreement, the practice
In 2023, OCR settled with a telehealth platform for $1.25 million after an investigation revealed the company's software transmitted protected health information
In 2023, OCR settled with a healthcare provider for over $1.25 million after an investigation revealed that protected health information was being shared through
In 2022, OCR settled with a health plan for $1.25 million after an investigation revealed that the organization had migrated protected health information to
In 2018, OCR settled with Filefax Inc. for $100,000 after the company left medical records — paper records containing protected health information — sitting in an
In December 2023, HHS published a Notice of Proposed Rulemaking (NPRM) that represents the most significant update to the HIPAA Security Rule since its original
Every month, OCR receives complaints about protected health information sent via unsecured text messages — a nurse texting a patient's lab results to a
In 2023, OCR settled with a dental practice in New England for $50,000 after an investigation revealed that staff members were routinely sharing patient
When OCR announced in late 2023 that the COVID-era telehealth enforcement discretion would not last forever, many healthcare organizations realized they had been operating telemedicine
In 2023, a dermatology practice in Connecticut paid $150,000 to settle an OCR investigation that traced back, in part, to unsecured electronic communications — including
Join healthcare organizations that trust HIPAA Certify for their workforce training and compliance tracking.