Call Us Today! 515-865-4591|Bob@hipaatraining.net

HHS

HHS OCR has fined Virtual Private Network Solutions, LLC, a HIPAA business associate, $90,000 for failing to comply with the requirements of the HIPAA Security Rule.

The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has announced a $90,000 settlement with Virtual Private Network Solutions, LLC (VPN Solutions), a Virginia-based business associate that provides data hosting and cloud services to covered entities and other business associates. This settlement addresses potential violations of the HIPAA Security Rule, which sets national standards for safeguarding electronic protected health information (ePHI). The investigation stemmed from a ransomware attack on VPN Solutions' systems. OCR Director Melanie Fontes Rainer emphasized the importance of proactive security measures, stating, “An accurate and thorough risk analysis is foundational to both HIPAA [...]

HHS OCR has fined Virtual Private Network Solutions, LLC, a HIPAA business associate, $90,000 for failing to comply with the requirements of the HIPAA Security Rule.

Elgon Information Systems was fined $80,000 by the OCR for failing to conduct a risk analysis as required under the HIPAA Security Rule.

The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) announced today that Elgon Information Systems (Elgon), a Massachusetts-based company providing electronic medical record and billing support services to covered entities, has agreed to an $80,000 settlement for violations of the HIPAA Security Rule. OCR enforces HIPAA's Privacy, Security, and Breach Notification Rules, which outline the responsibilities of covered entities—such as health plans, healthcare clearinghouses, and healthcare providers—and their business associates in safeguarding protected health information (PHI). The HIPAA Security Rule establishes national standards to protect electronic PHI (ePHI) through administrative, physical, and technical safeguards. This settlement [...]

Elgon Information Systems was fined $80,000 by the OCR for failing to conduct a risk analysis as required under the HIPAA Security Rule.

Health Care Clearinghouse, Inmediata Health Group, Fined $250,000 for HIPAA Impermissible Disclosure, HIPAA Security Rule failures

Today, the U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR) announced a settlement with Inmediata Health Group, LLC (Inmediata), a health care clearinghouse, over potential violations of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Security Rule. This follows a complaint to OCR that HIPAA-protected health information was accessible to search engines like Google on the internet. "Health care entities must ensure that patient health information is not left accessible online to anyone with an internet connection," said OCR Director Melanie Fontes Rainer. "Effective cybersecurity requires being proactive and vigilant in identifying risks and [...]

Health Care Clearinghouse, Inmediata Health Group, Fined $250,000 for HIPAA Impermissible Disclosure, HIPAA Security Rule failures

Children’s Hospital Colorado Fined $548,265 for HIPAA Privacy and Security Rules Violations by OCR

Today, the U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR), announced a civil monetary penalty of $548,265 against Children’s Hospital Colorado for violations of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy and Security Rules. These violations were reported in breach reports received in 2017 and 2020, relating to email phishing and cyberattacks. OCR is responsible for enforcing the HIPAA Privacy, Security, and Breach Notification Rules, which outline the requirements that covered entities (such as health plans, health care clearinghouses, and most health care providers), and business associates must follow to protect the [...]

Children’s Hospital Colorado Fined $548,265 for HIPAA Privacy and Security Rules Violations by OCR

HIPAA Security Rule Violations Penalty of $1.19 Million Impose by OCR on Gulf Coast Pain Consultants

Today, the Office for Civil Rights (OCR) within the U.S. Department of Health and Human Services (HHS) announced a $1.19 million civil monetary penalty against Gulf Coast Pain Consultants, LLC, operating as Clearway Pain Solutions Institute in Florida. This penalty comes in response to violations of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Security Rule following a breach report indicating that a former contractor had improperly accessed their electronic records system. OCR enforces the HIPAA Privacy, Security, and Breach Notification Rules, which outline the requirements that health plans, healthcare clearinghouses, most healthcare providers, and their business associates must [...]

HIPAA Security Rule Violations Penalty of $1.19 Million Impose by OCR on Gulf Coast Pain Consultants

Holy Redeemer Hospital Fined $35,581 Over Disclosure of Patient’s Protected Health Information, Including Reproductive Health Information by HHS Office for Civil Rights

The settlement highlights the importance of safeguarding the privacy of PHI, including reproductive health information. Today, the U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR) announced a settlement with Holy Redeemer Family Medicine (Holy Redeemer), a Pennsylvania hospital, regarding an alleged violation of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy Rule. The violation involved the impermissible disclosure of a female patient’s protected health information, including details related to reproductive health care. OCR enforces the HIPAA Privacy, Security, and Breach Notification Rules, which set the standards that covered entities (such as health plans, [...]

Holy Redeemer Hospital Fined $35,581 Over Disclosure of Patient’s Protected Health Information, Including Reproductive Health Information by HHS Office for Civil Rights

Mental Health Center Fined $100,000 by OCR for Failing to Provide Timely Access to Patient Records

Today, the U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR), announced a $100,000 civil monetary penalty against Rio Hondo Community Mental Health Center (“Rio Hondo”) in California. The penalty resolves an investigation into Rio Hondo's failure to provide a patient with timely access to their medical records. The Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy Rule’s right of access provisions require that individuals or their personal representatives have timely access to their health information (within 30 days, with the possibility of one 30-day extension) for a reasonable, cost-based fee. OCR enforces the HIPAA [...]

Mental Health Center Fined $100,000 by OCR for Failing to Provide Timely Access to Patient Records

The HHS Office for Civil Rights has imposed a $70,000 civil monetary penalty on Gums Dental Care for failing to provide timely access to patient records.

Today, the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) announced a $70,000 civil monetary penalty against Gums Dental Care, LLC, a solo dental practice in Maryland that provides family dental care. This penalty resulted from an investigation based on a complaint that Gums Dental Care failed to provide a patient with timely access to their medical records. According to the HIPAA Privacy Rule’s right of access provisions, individuals or their personal representatives must have timely access to their health information (within 30 days, with a possible one-time 30-day extension) for a reasonable, cost-based fee. “OCR [...]

The HHS Office for Civil Rights has imposed a $70,000 civil monetary penalty on Gums Dental Care for failing to provide timely access to patient records.

The HHS Office for Civil Rights has imposed a $240,000 civil monetary penalty on Providence Medical Institute following a cybersecurity investigation into a HIPAA ransomware incident.

The U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR), has announced a $240,000 civil monetary penalty against Providence Medical Institute in Southern California. This penalty follows an investigation into potential Health Insurance Portability and Accountability Act of 1996 (HIPAA) Security Rule violations prompted by a ransomware attack. Since 2018, ransomware attacks reported to OCR have increased by 264%. "Failing to implement all HIPAA Security Rule requirements fully leaves covered entities and business associates vulnerable to cyberattacks, compromising patient health information privacy and security," said OCR Director Melanie Fontes Rainer. "The healthcare sector must take cybersecurity seriously [...]

The HHS Office for Civil Rights has imposed a $240,000 civil monetary penalty on Providence Medical Institute following a cybersecurity investigation into a HIPAA ransomware incident.

The Department of Health and Human Services’ Office for Civil Rights has fined a nursing facility in New Jersey for not promptly granting access to patient records

Essex Residential Care, LLC, must pay $100,000 as a result of failing to adhere to HIPAA's Right of Access. The U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR), has declared a civil monetary penalty of $100,000 against Essex Residential Care, LLC, operating as Hackensack Meridian Health, West Caldwell Care Center (“Hackensack Meridian Health”), a skilled nursing facility offering long-term care and rehabilitation services. The penalty stems from an investigation by OCR into Hackensack Meridian Health's violation of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy Rule, specifically for failing to promptly provide a [...]

The Department of Health and Human Services’ Office for Civil Rights has fined a nursing facility in New Jersey for not promptly granting access to patient records
Go to Top