HHS OCR has fined Virtual Private Network Solutions, LLC, a HIPAA business associate, $90,000 for failing to comply with the requirements of the HIPAA Security Rule.
NuLLFiXThe U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has announced a $90,000 settlement with Virtual Private Network Solutions, LLC (VPN Solutions), a Virginia-based business associate that provides data hosting and cloud services to covered entities and other business associates. This settlement addresses potential violations of the HIPAA Security Rule, which sets national standards for safeguarding electronic protected health information (ePHI). The investigation stemmed from a ransomware attack on VPN Solutions' systems. OCR Director Melanie Fontes Rainer emphasized the importance of proactive security measures, stating, “An accurate and thorough risk analysis is foundational to both HIPAA [...]