PHI HIPAA Compliance: Protecting Health Data in 2024
In February 2024, OCR announced a $4.75 million settlement with a nonprofit health system that failed to conduct an enterprise-wide risk analysis — leaving the
Healthcare workforce HIPAA training strategies and solutions
In February 2024, OCR announced a $4.75 million settlement with a nonprofit health system that failed to conduct an enterprise-wide risk analysis — leaving the
In 2023, OCR settled with a dental practice in New England for $50,000 after it disclosed patient records to a third-party marketing firm without
In 2022, a dental practice in New England received a corrective action from OCR after an employee discussed a patient's treatment plan loudly
In 2023, OCR settled with a dental practice for $350,000 after an investigation revealed the organization had disclosed patient records to a third-party marketing
A compliance officer at a mid-size clinic recently told me her staff believed that PHI must be protected in all forms except verbal conversations — that
In 2023, OCR settled with a dental practice for $350,000 after an investigation revealed the organization had been disclosing patient records to a marketing
In February 2023, OCR settled with a dental practice for $195,000 after investigators found the organization had no written policies implementing the HIPAA Privacy
In 2023, OCR settled with a dental practice for $350,000 after investigators found the organization had addressed its Privacy Rule obligations but had done
In January 2024, a medical receptionist in Texas discovered her supervisor was accessing patient records for personal reasons — looking up neighbors, family members, even local
In early 2024, OCR settled with a telehealth provider for $950,000 after an investigation revealed the organization had deployed a cloud-based therapy platform without
In December 2022, OCR issued a bulletin explicitly warning healthcare organizations about the use of tracking technologies on websites and mobile apps — including pixels from
When HHS announced in late 2024 that the COVID-era telehealth enforcement discretion would not be extended indefinitely, many healthcare organizations realized they had been operating
Join healthcare organizations that trust HIPAA Certify for their workforce training and compliance tracking.