Business Associate HIPAA Agreement: What Must Be Included
In September 2023, OCR settled with a health system for $1.3 million after investigators found the organization had allowed a vendor to access protected
A collection of 212 posts
In September 2023, OCR settled with a health system for $1.3 million after investigators found the organization had allowed a vendor to access protected
In 2023, OCR settled with a business associate — a medical records management company — for $100,000 after an investigation revealed failures to safeguard protected health
Every month, patients contact OCR after discovering a hospital shared their medical records without authorization, a business associate lost a laptop containing thousands of patient
In 2023, OCR settled with a covered entity for $1.3 million after investigators discovered that workforce members had never received adequate HIPAA training — despite
In 2023, a mid-sized hospital system paid $1.3 million to settle with OCR after a series of incidents that all traced back to the
In 2023, OCR settled with a healthcare provider for over $100,000 after an investigation revealed that staff routinely sent unencrypted emails containing protected health
In 2023, OCR settled with a dental practice for $350,000 after an investigation revealed the organization had disclosed patient names, treatment records, and Social
In 2023, OCR settled with a solo dental practice in New England for $30,000—not because of a massive data breach, but because the
In 2023, the Department of Justice recovered over $2.68 billion in settlements and judgments related to healthcare fraud. Behind nearly every one of those
In 2023, OCR settled with a dental practice in New England for $50,000 after investigators found that the organization had no documented workforce training
In 2023, OCR settled with a healthcare provider for $50,000 after determining that the organization had disclosed protected health information using an authorization form
In February 2024, OCR announced a $4.75 million settlement with Montefiore Medical Center after a workforce member stole protected health information (PHI) of over
Join healthcare organizations that trust HIPAA Certify for their workforce training and compliance tracking.