News & Analysis as of

Settlement Health Insurance Portability and Accountability Act (HIPAA) Enforcement Actions

Troutman Pepper

Enzo Biochem Inc. Reaches Settlement With Connecticut, New Jersey, and New York AGs Over 2023 Data Breach

Troutman Pepper on

Molecular diagnostics company Enzo Biochem, Inc. has reached settlements resolving investigations in relation to a 2023 data breach by the attorneys general (AG) for Connecticut, New Jersey, and New York. Enzo has agreed to...more

Saul Ewing LLP

HIPAA Security Rule Settlement Results in $950,000 Payment by a Mid-Atlantic Health System

Saul Ewing LLP on

On July 1, 2024, the U.S. Department of Health and Human Services (“HHS”) Office For Civil Rights (“OCR”) announced a $950,000 settlement with Heritage Valley Health System (“Heritage Valley”) and a three-year Corrective...more

Skadden, Arps, Slate, Meagher & Flom LLP

HHS Office for Civil Rights Reaches Second Health Care Ransomware Settlement

The Department of Health and Human Services (HHS) Office for Civil Rights (OCR) recently announced its second settlement in four months growing out of a ransomware attack on a health care business. Maryland-based Green Ridge...more

Saul Ewing LLP

HHS OCR Issues Its Most Recent HIPAA Annual Report and a Second Ransomware Settlement

Saul Ewing LLP on

On February 14, 2024, the U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR) issued two reports to Congress as required by the Health Information Technology for Economic and Clinical Health...more

Saul Ewing LLP

NYC Hospital Agrees to Pay $4.75 Million as Part of a HIPAA Settlement

Saul Ewing LLP on

On February 6, 2024, the HHS Office for Civil Rights (“OCR”) announced a settlement with Montefiore Medical Center (“MMC”) for alleged HIPAA Security Rule violations and MMC agreed to pay $4.75 million and enter into a...more

Health Care Compliance Association (HCCA)

OCR Ends Year With Settlements That Tread Old Ground, Says New Rules Are Coming—Someday

If the penultimate enforcement settlement of 2023 issued by the HHS Office for Civil Rights (OCR) sounds familiar, that’s with good reason. And the last one of the year should ring some bells, too....more

Arnall Golden Gregory LLP

OCR Announces 46th Right of Access Settlement

The U.S. Department of Health and Human Services, Office for Civil Rights (“OCR”) recently announced its 46th settlement under its Right of Access Initiative since it was initially launched in 2019. Allegations in the recent...more

Bricker Graydon LLP

HHS Issue Six Figure Penalty for Ransomware Attack

Bricker Graydon LLP on

Late last year, the Department of Health and Human Services (HHS) issued its first HIPAA settlement agreement involving a ransomware attack. In the press release announcing the settlement, HHS stated that they began...more

Dorsey & Whitney LLP

HIPAA on the Horizon in the New Year: Important Lessons from an Active 2023 and Regulatory Initiatives to Watch for in 2024

Dorsey & Whitney LLP on

2023 marked 20 years since the first compliance deadline under the Health Insurance Portability and Accountability Act’s (“HIPAA”) privacy rule. Despite the two decades of experience with HIPAA, compliance continues to remain...more

Patterson Belknap Webb & Tyler LLP

Multistate Coalition of State Attorneys General Secures $49.5 Million from Cloud Company Blackbaud for 2020 Data Breach

State regulators across the country continue to increase their focus on cyber security and data privacy compliance and enforcement. For years, cloud company Blackbaud, a service provider to thousands of nonprofit enterprises,...more

Saul Ewing LLP

News Article Results in $80,000 HIPAA Settlement by New York State Hospital

Saul Ewing LLP on

On November 20, 2023, the U.S. Department of Health and Human Services (“HHS”) Office for Civil Rights (“OCR”) announced an $80,000 HIPAA settlement with Saint Joseph’s Medical Center (“SJMC”) in New York State. The...more

Brooks Pierce

Business Associate Victim of Ransomware Attack Pays $100,000 to HHS OCR

Brooks Pierce on

Is your organization a business associate? You could be subject to enforcement action if you fail to protect health information within your control from ransomware attacks. In October, for the first time, the U.S....more

Health Care Compliance Association (HCCA)

OCR: UHC Admitted Worker ‘Error’ Left Records Request Languishing in the Mail, Pays $80,000

Start with a records request. Add a seven months’ wait. Stir in the chaos of the pandemic, with most employees working from home. Blend in a perhaps-neglected post office box. Bake for two-and-a-half years....more

Dorsey & Whitney LLP

HHS OCR Settles HIPAA Investigation with Business Associate for $350,000

Dorsey & Whitney LLP on

Over the past decade, the number of health care data breaches reported to the U.S. Department of Health and Human Services’ Office for Civil Rights (“OCR”) has increased dramatically. From 2009 to 2022, over 5,000 data...more

Robinson+Cole Data Privacy + Security Insider

MedEvolve OCR Settlement for $350,000 due to Alleged Failures to Protect Data

On May 17, 2023, the U.S. Department of Health and Human Services’ Office for Civil Rights (OCR) announced a settlement with MedEvolve, Inc. for $350,000. MedEvolve provides practice and revenue cycle management and practice...more

WilmerHale

FTC Continues Enforcement Focus on the Use and Disclosure of Health Information for Advertising

WilmerHale on

On Thursday, March 2, the FTC announced an enforcement action against BetterHelp, Inc., an online mental health counseling service, relating to claims that the company’s collection and use of consumer health data were unfair...more

Perkins Coie

FTC's Second Settlement in Weeks Highlights Scrutiny on Businesses Processing Health Data for Advertising

Perkins Coie on

On March 2, 2023, following a 4-0 vote, the Federal Trade Commission announced a complaint and proposed consent order with BetterHelp, Inc., an online counseling platform that allegedly disclosed consumer health data to...more

WilmerHale

Attorneys General Bring Multistate Data Breach Settlement Against DNA Testing Lab

WilmerHale on

On February 17, 2023, the state attorneys general of Pennsylvania and Ohio reached a settlement with Ohio-based DNA Diagnostics Center (“DDC”) for a 2021 data breach that affected 2.1 million individuals nationwide and...more

Clark Hill PLC

With Recent Settlements, HHS OCR’s HIPAA Right of Access Initiative Continues To Be a Focus of Enforcement

Clark Hill PLC on

OCR’s HIPAA Right of Access Initiative shows no signs of slowing down. On July 15, the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) announced the resolution of 11 more cases at a total of...more

Saul Ewing LLP

Keep Your PHI Out of the Trash! OCR Announces Large Settlement With a Medical Practice After PHI Found in a Dumpster

Saul Ewing LLP on

On August 23, 2022, the Office for Civil Rights (OCR) within the U.S. Department of Health and Human Services (HHS) announced a $300,640 settlement and a Corrective Action Plan (“CAP”) with New England Dermatology P.C., d/b/a...more

Shumaker, Loop & Kendrick, LLP

Client Alert: Latest HIPAA Enforcement Actions

The Office of Civil Rights (OCR) has released information on its latest Health Insurance Portability and Accountability Act (HIPAA) enforcement actions. The government continues to pursue investigations and administrative...more

BakerHostetler

OCR Announces Four Enforcement Actions

BakerHostetler on

On March 28, 2022, Health and Human Services, Office for Civil Rights (OCR) announced the resolution of four enforcement actions, three resolved in 2021 and one resolved in 2022. There are some interesting aspects of this...more

Saul Ewing LLP

Nebraska Children’s Hospital Agreed to Pay $80,000 in OCR’s Twentieth HIPAA Right of Access Initiative

Saul Ewing LLP on

On September 10, 2021, the Office for Civil Rights (“OCR”) at the U.S. Department of Health and Human Services (“HHS”) announced the twentieth settlement of an enforcement action under its HIPAA Right of Access Initiative...more

Arnall Golden Gregory LLP

Continuation of OCR’s Right of Access Initiative with a Nineteenth Settlement

On June 2, 2021, the Office for Civil Rights (OCR) at the U.S. Department of Health and Human Services (HHS) announced the 19th Resolution Agreement in the Health Insurance Portability and Accountability Act (HIPAA) Right of...more

Saul Ewing LLP

OCR Settles Nineteenth Investigation in HIPAA Right Of Access Initiative

Saul Ewing LLP on

On June 2, 2021, the Office for Civil Rights (OCR) within the U.S. Department of Health and Human Services (HHS), announced that the Diabetes, Endocrinology & Lipidology Center, Inc., (DELC) agreed to pay $5,000, enter into a...more

54 Results
 / 
View per page
Page: of 3

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide