HIPAA Retention Policy: What You Must Keep and For How Long
In 2023, OCR settled with a dental practice for $350,000 after an investigation revealed the organization had no documentation of its risk analysis, policies,
HIPAA Security Rule requirements and implementation
In 2023, OCR settled with a dental practice for $350,000 after an investigation revealed the organization had no documentation of its risk analysis, policies,
In February 2024, OCR announced a $4.75 million settlement with a hospital system that had failed to conduct an enterprise-wide risk analysis for over
In 2023, OCR settled with a Louisiana medical group for $480,000 after a HIPAA security incident involving a stolen unencrypted laptop — an incident the
When OCR investigates a covered entity and discovers years of noncompliance, one of the most common — and least persuasive — defenses is confusion about when HIPAA
In 2023, a small dental practice in Texas received a $50,000 penalty from the Office for Civil Rights after a workforce member disclosed protected
In 2023, OCR settled with a Florida-based health system for $1.2 million after an investigation revealed — among other deficiencies — that the organization had no
In March 2024, a small dental practice in Florida agreed to a $50,000 settlement with OCR after an investigation revealed that none of its
In February 2023, OCR settled with a healthcare provider for $1.3 million after finding systemic failures to comply with basic HIPAA laws — failures that
In 2023, a dental practice in Texas paid a $50,000 settlement to OCR after a staff member texted a patient's treatment details
HIPAA stands for the Health Insurance Portability and Accountability Act of 1996. Understanding the full HIPAA meaning requires examining how this federal law shapes healthcare operations, privacy requirements, and compliance obligations.
When OCR settled with a major health system in 2017 for $2.5 million after a breach involving an unencrypted laptop containing protected health information
In 2023, OCR settled with a dental practice in New England for $50,000 after an investigation revealed that no member of the workforce — including
Join healthcare organizations that trust HIPAA Certify for their workforce training and compliance tracking.