HIPAA Advice

Why Medical Device Compliance Is Growing More Important Every Year

You don’t have to look very far to see the everyday applications of the medical device industry. They’re in the new technology and equipment in doctors’ offices, hospitals, and medical clinics. They surface in the expanding repertoire of devices that patients can use at home, expanding healthcare access and convenience. And they’re in the medical implants that often address serious health problems, including everything from pacemakers to stents to hip replacements to spinal fusion.

All these products are considered part of the medical device industry, which academic database ScienceDirect defines as a sector focused on the development, manufacturing, and distribution of devices that provide medical support and improve health outcomes, leveraging advances in biotechnology and bioengineering. A rapidly growing segment of the global economy, the medical device industry was valued at around $570 billion in 2025. It is expected to surpass $600 billion in 2026, before touching one trillion dollars sometime over the next decade.

Medical Device Compliance Defined

Like many large, lucrative industries, medical device manufacturers must adhere to a range of regulations imposed by the markets in which they operate. These regulations are developed and implemented to ensure that the industry’s products are safe, effective, and regularly monitored over the course of their lifetimes in the marketplace.

Due to the inherent risks involved, medical device manufacturing is an extensively regulated industry. Patients’ health, physical capabilities, and even lives are at stake when it comes to these technologies, and because of this, manufacturers have considerable legal responsibilities in countries like the U.S., the U.K., and Canada, as well as economic blocs like the European Union. Violating these regulations can trigger serious consequences, too, including penalties of $100,000 or more and imprisonment in cases of criminal negligence.

The World’s Major Medical Device Regulations

While the medical device sector spans the entire globe, industry regulations, and the legal obligations they impose, differ from one country to the next.

The U.S.: FDA and QSMR

The U.S. regulates medical devices through the Food and Drug Administration (FDA), which determines legal obligations based on three different risk categories. In addition to these classifications, medical device manufacturers must obtain FDA clearance to sell and market their devices, adhere to a Quality Management System Regulation (QSMR) harmonized to ISO 13485, and carry out post-market surveillance by monitoring defects, malfunctions, and other adverse events.

The EU: the MDR

In 2021, the EU replaced its Medical Device Directive (MDD) with the Medical Device Regulation (MDR), a change many describe as the largest shift in medical device compliance in years. The MDR imposes stricter requirements than its predecessor, with a higher threshold for clinical evidence and an expectation that manufacturers carry out post-market clinical follow-up to confirm that devices are working as intended and marketed.

In addition, the EU strengthened its requirements for the notifying bodies that certify devices for CE markings, reducing the number of organizations authorized to issue certifications.

The U.K. and the MHRA

To sell medical devices in the United Kingdom, manufacturers and importers must obtain a UKCA marking. Prior to 2021, products were classified into three different categories, with specific directives regulating each of them:

  • Directive 90/385/EEC applies to active implantable medical devices.
  • Directive 93/42/EEC applies to medical devices.
  • Directive 98/79/EC applies to in vitro diagnostic medical devices.

Today, businesses must get their devices registered and certified through the Medicines and Healthcare products Regulatory Agency (MHRA), the government body responsible for post-market surveillance.

Canada’s CMDR

Canada regulates medical devices through the nation’s Medical Devices Directorate (MDD), a government agency responsible for evaluating the safety and effectiveness of medical technology. Devices are classified into four different risk categories, and products that are categorized in Class II, Class III, or Class IV must all obtain licenses to sell their products.

Products in these three classes must undergo a rigorous review process. During this process, the manufacturer submits a completed application for a license; the MDD reviews the application; and the MDD then issues a license where applicable. In addition to issuing licenses, the directorate also conducts post-market surveillance. According to the Canadian government, if a medical device is found to no longer meet safety and effectiveness requirements, the MDD may suspend its license or ask the manufacturer to recall or refit the medical device.

An Evolving Compliance Landscape

In recent years, medical device compliance has grown more demanding all over the world. In many countries, manufacturers are now responsible for a range of regulatory responsibilities, including but not limited to:

  • Ensuring the safety of their devices.
  • Adhering to material regulations, including substance bans, maximum thresholds, and other restrictions.
  • Communicating and disclosing information to the public.
  • Carrying out post-market surveillance in accordance with regulatory requirements.

According to scientific publisher Elsevier, the number of regulations for medical device manufacturers increased 64% between 2015 and 2022, and the landscape has continued expanding since. One statistic that puts the sector’s regulatory obligations in perspective: U.S. manufacturers spend, on average, around $24 million on FDA-related requirements when bringing a single medical device from initial concept to market. For devices classified in the highest-risk Class III by the FDA, that figure rises to $75 million. In the EU, research suggests that the recent transition from the MDD to the MDR has increased regulatory costs on manufacturers up to tenfold.

Medical device compliance is not only becoming more costly. It is also becoming more time-intensive. Manufacturers operating in the U.S. can expect to spend anywhere between a few weeks and eight months working through the FDA’s regulatory approval process, with significant variance depending on the complexity and potential risks of the device. In other countries and regions, this path takes longer. Companies operating in the EU should prepare to commit a year or longer to the compliance process, while businesses in Japan spend between one and three years working to gain regulatory approval for new medical devices, placing Japan among the countries with the longest medical device approval timelines.

Given the time and financial resources required for regulatory adherence, manufacturers need to fully understand and meet their legal obligations to access the large, expanding global marketplace for medical devices.

How Medical Device Manufacturers Can Achieve Regulatory Compliance

Given the stakes associated with products that impact individual health and well-being, medical device manufacturers need to treat regulatory compliance as a major priority. Violations of the MDD, the QSMR, or the MHRA, among other directives, carry substantial financial and legal consequences.

Understand All Regulations That Apply To Your Business

In order to practice effective compliance, manufacturers first need to understand the scope of their responsibilities. The first step in doing that is identifying what specific regulations apply to them and their products. Organizations should review all the countries where their product is manufactured, imported, or sold, and what those nations’ legal obligations are for medical devices.

Medical device regulations remain in an early stage of development. The landscape remains fragmented and heterogeneous, with little harmonization between nations. Businesses must remember that achieving adherence with one directive does not prevent them from violating another.

Carry Out Necessary Steps for Certification

After establishing the scope of their obligations, manufacturers must then begin the process of gathering all the information required to achieve certification with the applicable regulatory bodies. For the more demanding national directives, this may include a number of individual steps:

  • Confirm product classification.
  • Reach out to a notified body or other accredited third-party organization.
  • Work with the notified body to compile all necessary documentation, including device descriptions, bills of materials (BOMs), general safety and performance requirements (GSPR), and risk management standards set by the International Organization for Standardization (ISO 14971).
  • Prepare a clinical evaluation report that pulls together clinical data, risks and benefits, and the intended purpose of the device.
  • Establish a plan for carrying out post-market clinical follow-up and implementing a post-market surveillance system.

While these steps vary from one regulation to the next, companies operating in multiple national markets should be prepared to fulfill most or all of them.

Foster Expertise and Develop Resources for Post-Market Surveillance

The post-market responsibilities imposed by directives like the MDD cannot be haphazard or ad-hoc. Organizations should have an established framework in place, with dedicated compliance professionals and a clear process for reviewing market data, issuing safety reports, and summarizing clinical performance. Post-market clinical follow-up (PMCF) and post-market surveillance (PMS) are strict obligations that can derail a product’s rollout or longevity when neglected, even after a device has reached the marketplace.

Leverage Third-Party Compliance Tools

The medical device and technology industry is comprised of many small and midsized businesses (SMBs), plenty of whom do not have the internal resources or bandwidth to effectively manage all the compliance obligations the sector imposes. In these cases, manufacturers can utilize a compliance tool that helps them understand their legal responsibilities, collects all the necessary compliance data, and submits technical documentation and clinical evaluations to the appropriate regulatory body. These software tools can support organizations through a regulatory process that is otherwise complex, lengthy, and difficult for smaller companies with limited bandwidth.

The post Why Medical Device Compliance Is Growing More Important Every Year appeared first on The HIPAA Journal.

What is a HIPAA Audit Checklist?

A HIPAA audit checklist is a document covered entities and business associates should use to audit compliance with the standards of the HIPAA Administrative Simplification Regulations applicable to their operations.

HIPAA Audit ChecklistAn internal HIPAA audit checklist differs from an external HIPAA audit checklist inasmuch as an external HIPAA audit checklist is designed to meet specific criteria of the OCR audit protocol, CMS’ compliance review program, or a third-party’s certification requirements.

By comparison, an internal HIPAA audit checklist is a comprehensive document that covers all areas of an organization’s compliance obligations. However, as different organizations have different compliance obligations, there is no “one-size-fits-all” internal HIPAA audit checklist.

Covered entities and business associates should review the following content, determine which standards of the HIPAA Administrative Simplification Regulations apply to their operations, and develop a HIPAA internal audit checklist that meets their requirements. The checklist should then be used as a HIPAA compliance audit checklist to identify gaps in compliance and implement measures to fill gaps.

hipaa audit checklist - thehipaajournal.com

Administrative Requirements Audit Checklist

The Administrative Requirements of HIPAA (Part 162) cover areas such as Unique Health Identifiers, Transaction Rules, and Code Set Standards. Covered entities that conduct claims processing or administration in-house, and business associates that provide billing and claims management services for covered entities, are required to comply with the standards of this Part.

Generally, there are only three areas of compliance organizations may need to include on an internal HIPAA audit checklist – the operating rules, the transaction rules, and documentation.

  • Verify compliance with the operating rules for eligibility, claims status, and electronic funds transfer/remittance advice.
  • Test transactions for compliance using the Administrative Simplification Enforcement and Testing Tool (ASETT).
  • Document policies, procedures, and test results for when the documentation is required for a compliance review.

While violations of the Administrative Requirements have never yet resulted in a civil monetary penalty, CMS has the authority to fine covered entities and business associates for noncompliance with Part 162 if an organization fails a CMS HIPAA audit and subsequently fails to comply with a corrective action plan. In the year to May 2023, 51% of organizations failed compliance reviews and were issued with a corrective action plan. (Reports for 2024 and 2025 have not been published).

HIPAA Privacy Rule Audit Checklist

The HIPAA Privacy Rule only has two basic HIPAA audit requirements – to protect individually identifiable health information from impermissible uses and disclosures, and to give individuals rights over their protected health information. To comply with these two requirements, organizations subject to the HIPAA Privacy Rule must comply with up to fourteen sets of standards depending on the nature of their operations.

Why “up to” fourteen? This is because, while all covered entities are required to comply with the HIPAA Privacy Rule, some standards do not apply to all types of organizations – for example, some standards apply to only health plans. Some business associates may be required to comply with specific HIPAA Privacy Rule standards depending on the service being provided for or on behalf of a covered entity and/or on the terms of their Business Associate Agreement with the covered entity.

All organizations subject to HIPAA compliance should review the following list, determine which applies to their operations, and add the relevant items to a HIPAA compliance audit checklist.

1. Designate a HIPAA Privacy Officer

Although most organizations will be familiar with this requirement, it is essential a member of the workforce is designated the role of Privacy Officer to be the point of contact for patients/plan members, workforce members, and regulatory agencies. The HIPAA Privacy Officer also has the responsibility to develop and implement HIPAA-compliant policies and procedures.

2. Understand What Constitutes PHI

There is a lot of misunderstanding about PHI, due to which some organizations can be unnecessarily overprotective with data, while others can be a little too carefree. Not only is it important to understand what constitutes PHI; but, for the sake of security and efficiency, to develop procedures for securing PHI in the minimum number of designated record sets practical.

3. Permissible Uses and Disclosures

Make sure all members of your organization´s workforce understand the difference between required, permissible, and attestable uses and disclosures of PHI, uses and disclosures of PHI for which an individual should be given an opportunity to consent or object, and uses and disclosures of PHI for which an individual´s written HIPAA authorization is required.

4. Procedures for Obtaining Authorizations

Every covered entity should have procedures for obtaining and managing authorizations so that if an individual exercises the right to revoke an authorization, the revocation can be actioned without delay. Procedures should also exist for (for example) withdrawing any information about the patient that has been used in fundraising or marketing material.

5. Notices of Privacy Practices

Every patient or plan member must be given a Notice of Privacy Practices when first attending a healthcare facility or enrolling in a health plan. The Notice must contain details of how PHI may be used or disclosed without an authorization, when it may only be used with the individual´s authorization, the rights of the individual to request privacy protection or copies of PHI.

6. Procedures for Responding to Requests for Privacy Protection

Individuals have the right to request restrictions on certain uses and disclosures – which can be situation-specific – and request to restrict how they are contacted by a covered entity or business associate. Organizations must have procedures in place to respond to requests for privacy protection, manage requests, and document oral terminations of requests.

7. Procedures for Responding to Requests for Access, Correction, and Transfer

The failure to provide access to health information, correct it when necessary, and transfer it to other providers when requested is one of the leading causes of complaints to HHS’ Office for Civil Rights. In an attempt to reduce the number of complaints, the agency is increasing its enforcement action against organizations that fail to respond to requests in a timely manner.

8. Procedures for Maintaining an Accounting of Disclosures

Individuals have the right to request an accounting of disclosures of their PHI for the six years prior to the request being made. However, not all disclosures have to be accounted for. It is important that covered entities understand which disclosures have to be accounted for and adopt procedures for maintaining an accounting of disclosures for each individual.

9. Workforce Training

Under the Privacy Rule, the training requirements are limited in scope to members of the workforce to whom HIPAA policies and procedures apply. However, basic HIPAA training should be provided to all members of the workforce in order to mitigate the risk of impermissible disclosures due to a lack of knowledge and reduce the risk of human error.

10. Documentation

Documentation is a requirement of nearly every standard in the HIPAA Privacy Rule, and organizations required to comply with the standards must put procedures in place for documenting policies and procedures, Notices of Privacy Practices, individual authorizations, workforce training, etc., and retaining policies and procedures for at least six years since they were last in force.

Organizations subject to the HIPAA Privacy Rule should also review the General Provisions of Part 164 – a section of the Administrative Simplification Regulations not covered by a “Rule”. These provisions primarily apply to Hybrid Entities, Affiliated Entities, and Organized Health Care Arrangements, and cover restricting access to PHI to only those who are authorized to access it within their roles and safeguarding PHI from non-covered areas of the organization.

HIPAA Security Rule Audit Checklist

Compared to the potential complexity of a HIPAA Privacy Rule audit checklist, a HIPAA Security Rule audit checklist is relatively straightforward. Not only does the HIPAA Security Rule contain far fewer standards than the HIPAA Privacy Rule, but the standards within the HIPAA Security Rule are less open to interpretation. The Security Standards General Rules also allow covered entities and business associates a “flexibility of approach” about how the standards are implemented.

To help organizations compile a HIPAA audit checklist for the HIPAA Security Rule, the Office of the National Coordinator for Health Information Technology (ONC) and HHS’ Office for Civil Rights have jointly produced a HIPAA Security Risk Assessment (SRA) Tool. Organizations can use the tool online or download as an Excel document to fulfill the risk assessment requirements of the Security Rule. However, this tool may not be suitable for all organizations; and before using it, it is advisable to consider the following questions:

1. Has your organization designated a HIPAA Security Officer?

This can be the same person as the HIPAA Privacy Officer but they need to be qualified for the position inasmuch as they have to design, implement, and enforce security policies and procedures. Ideally, it is best to designate this role to a senior member of the IT team.

2. Have you identified from where ePHI originates?

In order to protect ePHI from unauthorized access, disclosure, alteration, or deletion, you have to know from where ePHI originates, where it is maintained, and to where it is transmitted. Effectively, you need to create an audit trail for all ePHI in your organization´s possession.

3. Do you know how users access ePHI?

Before using the ONC/OCR Security Risk Assessment Tool, you need to conduct an inventory of devices used to access ePHI and the media on which it is stored. This not only includes onsite devices and servers, but also devices used to access ePHI remotely.

4. What security software is already in place?

As a covered entity or business associate, you are required to implement measures to mitigate threats from malware, ransomware, and phishing. Many organizations already have security measures – such as email and web filters – in place to mitigate threats.

5. What role-based access controls are already in place?

Similar to the previous item, many organizations already utilize role-based access controls to control what information users can access. It is far easier to adjust existing controls to comply with the Security Rule standards than start from scratch.

6. What other security mechanisms do you already use?

Due to the “flexibility of approach” clause and the fact that some implementation specifications are addressable, it may be possible to comply with many HIPAA Security Rule standards by enforcing the use of existing security mechanisms – i.e., PIN lock, automatic log-off, password managers, etc.

7. What processes already exist for reporting security incidents?

Most organizations should already have processes in place to flag suspect emails, malware, and other anomalies. These are usually sufficient for internal compliance with the HIPAA Security Rule – not forgetting that business associates are required to report all security incidents to covered entities.

8. Does the organization already have a security awareness training program?

The likelihood is that most organizations will have some form of security awareness training, and all that may be necessary for the training to meet the General Requirements of the HIPAA Security Rule (§164.406) is to tweak it to be more HIPAA-centric and ensure the training is documented.

9. Does the organization enforce a scaled sanctions policy?

Enforcing a scaled sanctions policy is an important step toward HIPAA compliance because it serves as a reminder to members of the workforce that minor or repeated violations of HIPAA can have consequences.

10. Does the organization have a contingency or emergency action plan?

Developing a contingency plan for foreseeable emergency events that may threaten the confidentiality, integrity, and availability of ePHI is a requirement of HIPAA. You may need to review the SRA Tool to ensure you have every type of emergency covered.

Although this HIPAA Security Rule HIPAA audit checklist is relatively basic with regards to the questions it asks, it is advisable to start a journey to HIPAA compliance by assuming zero knowledge – rather than assuming an existing degree of knowledge as the SRA Tool does. In addition, when implementing new measures, it is a best practice to test members of the workforce on what information they have absorbed rather than assume they have understood the new measures in one explanation.

HIPAA Audit Log Requirements

Whether you use a HIPAA Security Rule Audit Checklist or the SRA Tool, it is important not to overlook the HIPAA audit log requirements. The HIPAA Security Rule requires covered entities and business associates to implement hardware, software, and/or procedural mechanisms that record and examine activity in information systems that contain or use electronic Protected Health Information.

Audit logs enable covered entities and business associates to identify risks associated with events such as unauthorized access, impermissible disclosures, application flaws, and suspicious activities. They can also be used to provide forensic evidence following a security incident or data breach so measures can be put in place to prevent a reoccurrence.

The HIPAA Security Rule does not specify what data needs to be collected by audit logs or how frequently logs should be reviewed. HHS also acknowledges that different software solutions and applications record and examine system activity in different ways. For this reason, it can be beneficial for covered entities and business associates to implement HIPAA compliance software that can monitor all system activity and flag issues for further investigation.

Breach Notification Rule Audit Checklist

As business associates are required to notify covered entities of all security incidents (not just those that result in a breach of unsecured ePHI), business associates will need to use a different Breach Notification Rule audit checklist than a covered entity – who can use a HIPAA breach notification tool to determine whether a security incident is reportable or not. However, both Breach Notification Rule audit checklists will share some common items – for example:

  • How did the breach/security incident occur?
  • How has the impact of the breach/security incident been mitigated?
  • What should be done to prevent the breach/security incident from happening again?

It is also the case that procedures should be in place and responsibilities assigned for notifying covered entities of a security incident or for covered entities notifying HHS’ Office for Civil Rights and impacted individuals of a breach of unsecured ePHI. As with all other areas of HIPAA compliance, the procedures, all breaches/security incidents, and their outcomes must be documented and the documentation retained for a minimum of six years.

Advice for Developing and Completing HIPAA Audit Checklists

Integrating every element of HIPAA compliance into a single HIPAA audit checklist can be challenging and – due to the checklist’s comprehensiveness – potentially leave gaps that lead to compliance failures. There are two ways to overcome this challenge. Either divide the HIPAA audit checklist into smaller, more manageable units, or engage the services of a compliance professional to help you with both the development and the completion of the checklist.

One of the advantages of choosing the latter option is that compliance professionals have the experience to assess an existing checklist, determine how much help you need, and provide as much help as necessary to produce an accurate and comprehensive checklist. This approach has the benefit of preventing the scenario in which you are looking for threats that do not exist in standards that do not apply to your organization – saving your time and your organization’s money.

FAQs

What are the HIPAA Administrative Simplification Regulations?

The HIPAA Administrative Simplification Regulations are the “Administrative Data Standards and Other Requirements” that were developed as a result of the passage of HIPAA (Title 45, Subtitle A, Subchapter C of the Code of Federal Regulations).

The Regulations not only include the standards for the Administrative Requirements and the HIPAA Privacy, Security, and Breach Notification Rules, but also the General Administrative Provisions, the General Security and Privacy Provisions, and the Enforcement Rule.

Could CMS issue a civil monetary penalty for noncompliance?

The Centers for Medicare and Medicaid Services (CMS) has the same authority to impose sanctions on noncompliant organizations as HHS’ Office for Civil Rights. In theory, CMS could impose a fine of up to $2,134,831 on a covered entity or business associate who repeatedly failed to comply with the Administrative Requirements due to willful neglect.

Why are business associates required to comply with the Privacy Rule?

The applicability standard of the HIPAA Privacy Rule (§164.104) was amended via the Final Omnibus Rule in 2013 to read “Where provided, the standards, requirements, and implementation specifications adopted under this part [the HIPAA Privacy Rule] apply to a business associate.”

This means that a business associate may need to develop policies and procedures relating to permissible uses and disclosures and for managing access requests if an individual’s ePHI is maintained in a separate designated record set from that of the covered entity.

Does a business associate have to designate a Privacy Officer?

This depends on the nature of the business associate’s operations and the potential for interactions with the public and regulatory authorities. If there is likely to only be minimal interaction, the role of Privacy Officer could be designated to a Security Officer.

What is considered PHI under HIPAA?

This is possibly the most frequently asked question relating to HIPAA compliance because what is considered PHI under HIPAA is complicated – so complicated that we have dedicated a full-page article to answering this question.

Why is the ONC/OCR Security Risk Assessment Tool not suitable for all organizations?

According to the OCR’s website, “the tool’s features make it useful in assisting small and medium-sized health care practices and business associates”. This implies that it is not suitable for health plans, healthcare clearinghouses, and larger organizations.

In addition, the tool assumes a certain level of knowledge and that a number of measures have already been implemented to comply with HIPAA Security Rule standards. If your organization is taking its first steps towards HIPAA compliance, you may find the tool too advanced for your needs.

How might an organization already have role-based access controls in place?

Many organizations use identity and access management services such as Microsoft AD, Okta Lifecycle Management, or Open LDAP (etc.) to control who in the organization has access to systems and databases. These services can often be used to comply with the HIPAA Security Rule access requirements.

What is the difference between a HIPAA compliance audit checklist and a healthcare compliance audit checklist?

The difference between a HIPAA compliance audit checklist and a healthcare compliance audit checklist is that a HIPAA compliance checklist helps organizations audit their compliance with HIPAA, while a healthcare compliance checklist helps organizations audit their compliance with all applicable federal, state, and local regulations related to their healthcare activities (i.e., CMS’ Medicare regulations, OSHA workplace regulations, and state licensing requirements).

What are 3 important components of a HIPAA security audit?

All components of a HIPAA security audit are important. However, the 3 elements of a HIPAA security audit most organizations should focus on include:

  • An inventory and audit trail of ePHI. If you do not know where ePHI originates, where it is stored, how it is used, and how it is disclosed, it will be impossible to implement measures to safeguard the confidentiality, integrity, and availability of health information.
  • The implementation and configuration of software. It is often not sufficient to implement software described as “HIPAA compliant” to comply with the HIPAA Security Rule. The software also has to be configured to mitigate threats to health information.
  • Workforce training and compliance monitoring. All members of the workforce must receive security awareness training even when they do not have access to ePHI. It is also important to monitor compliance with the security awareness training.

The post What is a HIPAA Audit Checklist? appeared first on The HIPAA Journal.

HIPAA Compliance Software

The purpose of HIPAA compliance software is to provide a framework to guide a HIPAA-covered entity or business associate through the process of becoming HIPAA-compliant and support continued compliance with HIPAA.

The best HIPAA compliance softwareHIPAA compliance software helps administrators, business owners, practice managers, and compliance officers, many of whom manage compliance alongside other responsibilities and without a formal background in healthcare regulation, navigate the nuances of HIPAA and ensure all applicable provisions of the HIPAA Privacy, Security, and Breach Notification Rules are satisfied. The software also proves a company has made a good faith effort to comply with HIPAA by maintaining full documentation of compliance activities.

This ensures that if a company is audited by the HHS’ Office for Civil Rights (OCR) or is investigated by OCR or state attorneys general over a data breach, the organization can demonstrate no aspect of HIPAA has been missed, all policies and procedures are in order, members of the workforce have received HIPAA training, and appropriate technical, physical, and administrative safeguards have been implemented and are being maintained. Additionally, the right compliance software will include support if an investigation does occur, not just documentation beforehand.

It should be noted that the use of HIPAA compliance software will not absolve companies of liability in every circumstance (i.e., in the event of an employee violating HIPAA), but regulators do take a covered entity’s or business associate’s good faith efforts to comply with HIPAA into account when deciding whether a financial penalty or other sanction is appropriate. A well-documented compliance program, consistently maintained, is the strongest protection available if OCR ever investigates.

Avoid Taking Shortcuts with HIPAA Compliance Software

Many compliance solutions only address specific elements of HIPAA compliance, such as the risk assessment. While HIPAA risk assessment software is a good place to start, it only covers one required provision of the HIPAA Security Rule.

Software that only covers specific aspects of HIPAA compliance will not help covered entities and business associates assess and demonstrate they are fully compliant. Even if covered entities and business associates are confident about their compliance programs, it is best to use a comprehensive software solution that covers all the required and addressable implementation specifications of HIPAA, the HITECH Act breach notification requirements, and even state laws.

A comprehensive compliance solution does not need to be the most expensive option available. For many organizations, the most practical choice is often a solution that covers everything required without unnecessary complexity, and makes the ongoing work of staying compliant as straightforward as possible.

Best HIPAA Compliance Software

The best HIPAA compliance software is a comprehensive compliance solution that walks users through setting up, implementing, and maintaining HIPAA policies and procedures, tracks staff training, and ensures all appropriate safeguards are implemented to meet HIPAA Privacy and Security Rule requirements.

The best HIPAA compliance softwareMany compliance software solutions include templates for policies and HIPAA documents such as business associate agreements. Templates vary significantly in how useful they actually are in practice. Some require the user to understand enough about HIPAA and their own organization to complete them correctly, which can be a significant ask for a practice manager without a compliance background. Others provide static, one-size-fits-all documents that may not accurately reflect how a specific practice operates. Documentation that does not represent what a practice actually does can work against an organization during an investigation. The best solutions generate documentation specific to the organization rather than requiring users to build it themselves.

The top HIPAA compliance solutions also help with the management of business associates. Business associates can be fined directly for HIPAA violations, but HIPAA covered entities also have a responsibility to ensure vendors are fully compliant. A HIPAA breach at a business associate will have many negative implications for a covered entity.

Some HIPAA compliance software solutions allow covered entities to send self-audits to business associates, monitor the results of the audits, and track and maintain business associate agreements.

A good compliance solution will track employee training, ensure it is completed on schedule, and maintain documentation of who completed what and when. That documentation is what matters during an investigation. Continuing education credits are sometimes offered as part of HIPAA training programs, but for most staff completing HIPAA training they serve no practical purpose and are unrelated to HIPAA compliance requirements. The measure of good training is not whether it earns credits. It is whether it was completed, documented, and whether that record holds up if OCR asks to see it.

Last but not least, even the best HIPAA compliance software solutions are not guaranteed to resolve all HIPAA compliance issues. If problems are experienced, support staff should be available to guide you through the compliance process and answer any questions you may have about HIPAA. When evaluating support, look beyond whether it exists and ask how quickly responses come, how it is accessed, and whether it is included in the cost of the software or available only at an additional charge.

Software Ease of Use

For practice managers and administrators who are not compliance specialists, ease of use is one of the most important and frequently underestimated factors in whether a software solution delivers on its promise.

Many software users might only log into their compliance platform once a month or less. A solution that is not intuitive, or requires a support call to complete routine tasks, adds friction that discourages consistent use. The best solutions make it clear what needs to be done, guide the user through it, and require minimal time to maintain once the initial setup is complete.

Initial setup may require a time investment depending on your starting point – so don’t let that scare you off. But a well-designed solution should be completable in a matter of hours and should not require prior compliance expertise to get started. After setup, ongoing maintenance should be light enough that compliance does not become a recurring burden on staff.

What Compliance Software Will and Will Not Do

No compliance software eliminates the need for human input entirely. The role of a good solution is to remove the expertise requirement, automate what can be automated, and reduce the time required for the work that remains.

Someone at the organization will still need to complete tasks, review documentation, and ensure the program stays current. The difference between a good solution and a poor one is how much time and knowledge that requires. In general, a well-implemented compliance program should not be a significant ongoing time commitment once it is properly set up.

Be cautious of any solution that implies compliance can be achieved with no effort or input from the organization. Compliance requires the organization to accurately represent itself. Software can guide and automate that process, but it cannot replace the engagement of the people who know the practice.

Assessing Suitable HIPAA Compliance Software Vendors

Finding a suitable vendor of HIPAA compliance software can be a challenge. We suggest the following tips for finding a suitable software vendor to ensure the service provided for you is comprehensive and does not leave any unidentified gaps in your compliance efforts:

  • Avoid HIPAA training courses that promise compliance certification within a matter of minutes
  • Select vendors that offer compliance solutions tailored to your specific needs
  • Ensure somebody is available to answer any questions and guide you through the compliance process
  •  (and if that support is included in the cost)
  • Check the vendor offers a solution that supports continued compliance rather than simply providing a one-off assessment
  • Ask whether any customers have been through an OCR investigation while using the software and what the outcome was
  • Confirm how the software handles regulatory updates and how your documentation is updated when rules change
  • Research whether the vendor is endorsed by any medical associations or IT organizations

HIPAA Compliance Software Vs. HIPAA Compliant Software

The terms “HIPAA compliant software” and “HIPAA compliance software” are frequently used interchangeably by some software vendors, although the two terms mean something quite different.

“HIPAA compliance software” is more often than not an app or service that guides a business through its compliance efforts. This type of software can either help with specific elements of HIPAA compliance (i.e. HIPAA Security Rule risk assessments) or provide a total solution for every element of HIPAA compliance.

HIPAA compliant software is usually an app or service for healthcare organizations that includes all the necessary privacy and security safeguards to support HIPAA compliance – for instance, secure messaging solutions, hosting services, and secure cloud storage services. HIPAA compliant software does not guarantee compliance. It is the responsibility of users of the software solutions to ensure the software is used in a HIPAA-compliant manner.

If you are a vendor looking for information on how to make your software solution HIPAA compliant please click here.

 

 

Benefits of HIPAA Compliance Software–the hipaajournal.com

Summary

Finding the right compliance software is worth some due diligence. The consequences of getting it wrong are significant, and the ongoing cost of a quality solution is modest compared to the cost of an investigation, a fine, or a breach.

The right software will not make compliance effortless, but it will make it less effort. Look for a solution that covers everything required, generates documentation specific to your practice or business, keeps itself current as regulations change, and has a track record of supporting customers through real-world compliance situations.

For a more detailed framework to evaluate and compare specific solutions, download our free buyer’s guide.

Buyers Guide Best HIPAA Compliance SoftwareFree Buyer’s Guide

We have compiled a free buyer’s guide to choosing the best HIPAA compliance software. This includes a checklist for essential functionality, software specifications and business considerations. You can rate up to three different solutions for each area and compare your results. This guide to choosing compliance software can be downloaded by filling in the form on this page.

FAQs

Is HIPAA compliance software the same for covered entities and business associates?

HIPAA compliance software is not the same for covered entities and business associates. While both covered entities and business associates are required to comply with all “applicable” standards of the HIPAA Administrative Simplification Regulations, a covered entity would likely need more comprehensive guidance through the complexities of the HIPAA Privacy Rule. In addition, topics such as business associate management would most often be unique to covered entities.

What is the most important feature of HIPAA compliance software for covered entities?

The most important feature of HIPAA compliance software for covered entities depends on where gaps exist in their current program. For many practices the most pressing need is a complete, documented program they can stand behind if OCR ever investigates. A risk assessment is a required starting point, but the software should go well beyond that to cover all required elements of a HIPAA compliance program.

What is the most important feature of HIPAA compliance software for business associates?

The most important feature of HIPAA compliance software for business associates will again depend on whether gaps exist in the business associate’s compliance efforts and what they are. However, one of the most important benefits of HIPAA compliance software for business associates is understanding the role they play in handling patient data. Too often, business associates are unaware of the requirements they must follow when working with covered entities.

Is there any HIPAA software my organization should avoid?

With regards to HIPAA software your organization should avoid, be cautious of vendors who promise full compliance with no meaningful setup process or no documentation of how the program was built. Also be wary of training that requires no real engagement from staff. Anyone familiar with HIPAA will know that partial compliance is not compliance, so avoid vendors that offer compromise to the rule. Be equally cautious of solutions priced so low that it raises questions about what is actually included and who is available to help when a real situation arises

Where can I find out more about HIPAA compliance software?

The best HIPAA compliance softwareYou can find out more about HIPAA compliance software by clicking over to our page about the best HIPAA compliance software which covers requirements under (1) essential functionality, (2) software specifications and (3) business considerations.

What is the purpose of HIPAA compliance software?

The purpose of HIPAA compliance software is to provide a framework to guide HIPAA-covered entities and business associates through the process of becoming HIPAA-compliant and ensuring continued compliance with HIPAA and HITECH Act Rules. The software helps compliance officers navigate the nuances of HIPAA and ensures all applicable provisions of the HIPAA Privacy, Security, and Breach Notification Rules are satisfied.

How can HIPAA compliance software help during an investigation or audit by OCR inspectors?

HIPAA compliance software can help during an investigation or audit by OCR inspectors by providing full documentation of compliance efforts. The documentation demonstrates that the organization has made a good faith effort to comply with HIPAA, that all applicable policies and procedures are in order, and that workforce members have received training.

Does HIPAA compliance software absolve organizations of liability in the event of a data breach?

HIPAA compliance software does not absolve organizations of liability in the event of a data breach. It is a tool, and its effectiveness as a defense depends entirely on how well it has been used. A program that is set up carelessly or left out of date will not hold up in an investigation in the same way a well-maintained one will. However, an organization that has actively used its compliance software to build and maintain a complete, documented program is in a significantly stronger position when regulators investigate. The software creates the conditions for a good defense. The organization still has to use it properly.

What features should be included in the best software for HIPAA compliance?

The features that should be included in the best software for HIPAA compliance include features to help develop, implement, and maintain HIPAA policies and procedures, track staff training, ensure appropriate safeguards are implemented, and allow the customization of policies, procedures, and documentation. The best software for HIPAA compliance should also assist with the management of business associates and be supported by knowledgeable and available compliance experts.

Is there an officially recognized HIPAA compliance certification for software?

There is no official certification that declares an organization compliant. This is because HIPAA compliance is not a milestone you reach once a year, it is a program you constantly maintain. Some compliance providers offer badges or seals that organizations can display on their websites to signal a commitment to compliance practices. However, these carry no regulatory weight and do not constitute proof of compliance in an investigation.

Is there an officially recognized HIPAA certification for software vendors?

There is no officially recognized HIPAA certification for software products. A software vendor cannot be certified as HIPAA compliant in any official sense. If you are evaluating a software vendor or any third party that handles patient data on your behalf, the relevant document is a Business Associate Agreement, which does not certify that a vendor is HIPAA compliant, but it establishes their legal obligation to handle protected health information appropriately and creates accountability if they do not. Some vendors also hold a SOC 2 or HITRUST certification, which speaks to the security of their own systems and processes. This is a meaningful indicator of how a vendor manages data internally but it is distinct from HIPAA compliance and should never be treated as a substitute for a BAA.

 

The post HIPAA Compliance Software appeared first on The HIPAA Journal.

HIPAA Compliance for Medical Spas

Medical spas that collect health histories, administer injectable treatments, perform laser procedures, or operate under the supervision of a licensed physician are HIPAA-Covered Entities and must comply in full with the HIPAA Privacy Rule, the HIPAA Security Rule, and the HIPAA Breach Notification Rule. This compliance obligation applies regardless of whether the facility describes itself as a spa, a wellness center, or an aesthetic clinic. The presence of a licensed medical professional and the creation of protected health information (PHI) during clinical intake or treatment determines covered entity status, not the branding or ambiance of the business.

Many medical spa operators assume HIPAA applies only to hospitals, physician practices, or insurance companies. That assumption is incorrect and carries substantial regulatory risk. OCR enforcement actions have reached small practices and specialty providers, and civil monetary penalties under the HIPAA Privacy Rule apply equally to all covered entities regardless of size.

Medical Spas as HIPAA-Covered Entities

A medical spa becomes a HIPAA-Covered Entity when it employs or contracts with licensed healthcare providers who conduct clinical assessments, write prescriptions, or create treatment records in the course of delivering care. The touchpoint that triggers covered entity status is not the treatment itself but the creation, receipt, maintenance, or transmission of PHI in connection with that treatment.

PHI at a medical spa includes client intake forms that capture health history, medication lists, or allergy information; clinical notes documenting treatments such as neurotoxin injections or laser resurfacing; before-and-after photographs linked to a client’s identity and treatment record; prescription records for topical or injectable medications; and billing records that combine a client’s identity with a diagnosis or procedure code. Each of these data types falls within the definition of PHI under 45 CFR §160.103 and requires protection under applicable HIPAA rules.

Develop Internal HIPAA Policies and Procedures

The HIPAA Privacy Rule at 45 CFR §164.530(i) requires covered entities to implement policies and procedures that reasonably protect PHI and that govern day-to-day operational activities. For a medical spa, this obligation extends to every touchpoint where PHI is created, accessed, used, or disclosed.

Policies must address permissible and impermissible uses and disclosures of PHI. At minimum, a medical spa’s HIPAA policy framework should define how treatment records are accessed by clinical and non-clinical staff, who may discuss a client’s care and under what circumstances, how client identity is verified before PHI is disclosed in person or by telephone, and how the minimum necessary standard is applied when sharing information between staff members or with third parties.

The minimum necessary standard under 45 CFR §164.502(b) requires that workforce members access only the PHI needed to perform their specific job function. A front desk coordinator scheduling a follow-up appointment does not need access to a client’s full clinical notes. A laser technician reviewing contraindications does not need access to billing records. Policies must define these access boundaries in operational terms, not just regulatory language.

Medical spas frequently use before-and-after photographs in marketing materials. Using a client’s identifiable photograph for marketing purposes requires a valid HIPAA authorization that complies with 45 CFR §164.508. Authorization forms must contain all required core elements, must be written in plain language, and must be stored for a minimum of six years. Using a photograph without a compliant authorization constitutes an impermissible disclosure of PHI and a violation of the HIPAA Privacy Rule.

The Notice of Privacy Practices (NPP) required under 45 CFR §164.520 must be provided to each new client at the first point of service, posted in a visible location within the facility, and made available on the organization’s website if one exists. The NPP must be reviewed and updated whenever a material change affects an individual’s privacy rights or the organization’s permissible uses and disclosures.

Designate a HIPAA Privacy Officer and HIPAA Security Officer

The HIPAA Privacy Rule at 45 CFR §164.530(a) requires every covered entity to designate a HIPAA Privacy Officer responsible for developing and implementing the organization’s privacy policies and procedures. The HIPAA Security Rule at 45 CFR §164.308(a)(2) requires designation of a HIPAA Security Officer responsible for the policies and procedures governing the protection of electronic PHI (ePHI).

In a small or single-location medical spa, one individual may hold both roles. That individual must have sufficient authority and operational knowledge to fulfill both sets of obligations. Assigning these roles to a staff member without providing training, authority, or time to carry out compliance functions does not satisfy the regulatory requirement.

The Privacy Officer serves as the point of contact for client requests related to their HIPAA rights, including requests for access to records, amendments, restrictions on use, and accounting of disclosures. The Privacy Officer also receives and responds to internal reports of potential privacy violations and manages complaints filed with HHS. The Security Officer conducts or coordinates the organization’s security risk assessment, oversees technical and physical safeguards for ePHI, and leads workforce training on security practices.

Conduct a HIPAA Security Risk Assessment

The HIPAA Security Rule at 45 CFR §164.308(a)(1) requires covered entities to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI. This security risk assessment is not optional and is one of the most consistently cited deficiencies in OCR compliance investigations.

For a medical spa, the risk assessment must account for every system that creates, stores, transmits, or receives ePHI. This includes electronic intake platforms, appointment booking software, practice management systems, cloud-based storage solutions, email platforms used to communicate client information, and any mobile devices used by clinical staff. The assessment must document identified risks, rate the likelihood and potential impact of each risk, and produce an actioned remediation plan.

The risk assessment must be repeated whenever there is a material change to the organization’s operations, technology, or physical environment. Moving to a new electronic health record system, adding a new treatment modality that generates new data, or opening an additional location each triggers a reassessment obligation. All risk analyses and remediation documentation must be retained for a minimum of six years.

HIPAA Training for Medical Spa Employees

Medical spa employees face HIPAA compliance challenges that differ from those in larger healthcare settings due to the physical environment, staffing structure, and community dynamics in which most medical spas operate. The majority of medical spas are single-location businesses with small workforces, where the same staff member may handle clinical support, front desk duties, billing, and marketing simultaneously. That combination of limited resources and multitasking in publicly accessible reception areas increases the risk of inadvertent PHI disclosures. Medical spas serving local communities add a further layer of risk, as workforce members may face direct or indirect pressure from community members to disclose information about a client’s condition or treatment. These factors make role-specific, facility-focused HIPAA training a regulatory necessity rather than a supplement to generic compliance education.  The HIPAA training requirements under 45 CFR §164.530(b) mandate that covered entities train all members of their workforce on the policies and procedures developed to comply with the HIPAA Privacy Rule and HIPAA Breach Notification Rule, as necessary and appropriate for each individual’s role. Training must be provided to new workforce members within a reasonable period of joining the organization and repeated when material changes to policies or procedures occur.

At a medical spa, the workforce subject to HIPAA training includes every individual whose work involves PHI in any form. This includes physicians, nurse practitioners, physician assistants, registered nurses, licensed estheticians performing medical treatments, laser technicians, front desk and scheduling staff, billing personnel, and any contracted workers who access client records. The obligation covers part-time employees, temporary staff, and volunteers who handle PHI.

HIPAA Security Rule training must address how to create and manage secure passwords for systems containing ePHI, the requirement not to share login credentials with other staff members, the use of automatic logoff features on shared workstations and devices, the correct handling and disposal of devices that store ePHI, how to recognize phishing emails targeting healthcare businesses, and the obligation to report a suspected security incident to the HIPAA Security Officer immediately rather than attempting to resolve it independently.

Every training session must be documented. Documentation must include the date of training, the content covered, the names of all participants, and the training format. Where state law requires it, workforce members must provide written attestation that they completed the training. For example, Texas state law requires HIPAA training to be completed within 90 days of hire. Medical spa operators must confirm whether their state imposes specific training timeframes beyond the federal baseline requirement.

Establish Channels for Reporting HIPAA Violations

HIPAA incident management depends on workforce members having a clear and accessible mechanism to report potential violations internally. The HIPAA Privacy Rule at 45 CFR §164.530(d) requires covered entities to have a process for individuals to make complaints about the organization’s privacy practices. Internally, covered entities must ensure that workforce members can report concerns without fear of retaliation.

Medical spas should designate the Privacy Officer as the recipient of internal violation reports and make that designation known to all workforce members during training. Anonymous reporting channels, while not required by HIPAA, increase the likelihood that workforce members will report incidents they might otherwise conceal. Any PHI contained in an anonymous report must be handled with the same safeguards applied to other PHI within the organization.

Two-way communication is a component of an effective compliance program. Workforce members on the clinical floor frequently encounter privacy challenges not anticipated in formal policy documents. A front desk coordinator who regularly encounters family members requesting information about a client’s treatment plan, or a nurse who is asked to document a procedure in a system she lacks proper access credentials for, represents a compliance problem that policy revision or targeted training can address. Without a mechanism to surface these ground-level challenges, the compliance program operates on assumptions rather than operational reality.

Monitor HIPAA Compliance at the Operational Level

Policies and training produce HIPAA compliance only when monitored at the level where PHI is actually handled. For a medical spa, this means supervisors and the Privacy Officer must observe how client intake is conducted, how PHI is discussed at the reception desk, how treatment rooms handle the visibility of records, and how electronic devices storing ePHI are managed between client appointments.

Minor compliance shortcuts, such as discussing a client’s treatment in the waiting area or leaving a workstation logged in while unattended, are the entry point for a culture of non-compliance. When these behaviors go unaddressed, they become normalized and replicated. The appropriate response to a minor violation identified at the floor level is corrective action and retraining, not punitive sanction. The objective is correction before a pattern develops.

Audit log reviews for electronic systems containing ePHI should be conducted on a scheduled basis by the Security Officer. These reviews confirm that access to client records is consistent with each workforce member’s assigned role and flag anomalous access events that may indicate a security incident. Many electronic health record and practice management platforms generate access logs automatically. Using those logs as a compliance monitoring tool requires a process for regular review and documentation of findings.

Apply and Document a HIPAA Violations Sanctions Policy

The HIPAA Privacy Rule at 45 CFR §164.530(e) requires covered entities to apply appropriate sanctions against workforce members who fail to comply with the organization’s privacy policies and procedures. The HIPAA penalties framework applies to the covered entity, but internal sanctions govern the workforce member whose conduct created the compliance failure.

Sanctions must be proportionate to the nature and severity of the violation. A minor inadvertent disclosure by a new employee who has not yet received full training warrants a different response than a deliberate unauthorized access to a client’s records by a tenured staff member. The sanctions policy must define the range of responses available, including verbal warnings, written warnings, mandatory refresher training, suspension, and termination, and must be applied consistently across all roles and seniority levels.

The application of sanctions and the rationale for the sanction applied must be documented. Sanction records must be retained for a minimum of six years. Inconsistent application of the sanctions policy, or evidence that senior staff were treated differently from junior staff for equivalent violations, undermines the compliance program and creates legal exposure in enforcement proceedings.

Respond Promptly to HIPAA Violations and Breaches

The HIPAA Breach Notification Rule at 45 CFR §164.400 requires covered entities to notify affected individuals, HHS, and in some cases the media following the discovery of a breach of unsecured PHI. A breach is presumed notifiable unless the covered entity can demonstrate through a four-factor risk assessment that there is a low probability the PHI has been compromised.

For a medical spa, breach scenarios include unauthorized access to an electronic client database, a lost or stolen device containing unencrypted client records, an email sent to the wrong recipient containing PHI, and the impermissible posting of client photographs online. Each of these events triggers the obligation to conduct a breach risk assessment and, where notification is required, to notify affected individuals within 60 days of discovery.

Breaches affecting fewer than 500 individuals must be reported to HHS in an annual log submitted no later than 60 days after the close of the calendar year. Breaches affecting 500 or more individuals in a single state or jurisdiction require media notification in addition to individual and HHS notification, all within 60 days of discovery. All breach notifications, risk assessments, and remediation steps must be documented and retained.

Prompt internal response to a reported or discovered incident determines whether the organization can demonstrate a good-faith compliance posture in the event of an OCR investigation. Delayed responses, failure to investigate, and failure to notify on time are each independently sanctionable under the HIPAA Breach Notification Rule.

Use Business Associate Agreements

Medical spas routinely work with third-party vendors who access, store, or process client PHI on behalf of the covered entity. Each such vendor qualifies as a HIPAA Business Associate and requires a signed Business Associate Agreement (BAA) before any PHI is disclosed to them. Operating without a BAA in place constitutes a violation of the HIPAA Privacy Rule regardless of whether a breach has occurred.

Business associate relationships at a medical spa commonly include electronic health record and practice management software vendors, appointment booking and client management platforms, cloud storage services used to retain intake forms or photographs, billing and revenue cycle management companies, email marketing platforms that receive client contact information combined with service history, and IT support providers with remote access to systems containing ePHI.

A BAA must specify the permitted uses and disclosures of PHI by the business associate, require the business associate to implement appropriate safeguards, obligate the business associate to report breaches and security incidents to the covered entity, and include terms governing the return or destruction of PHI at the end of the relationship. Covered entities are responsible for monitoring whether their business associates operate in compliance with the terms of the agreement. If a covered entity knew or should have known of a pattern of non-compliance by a business associate and failed to act, the covered entity may share liability for the resulting HIPAA violation.

Maintain Full HIPAA Program Documentation

HIPAA compliance is an ongoing operational obligation, not a project with a completion date. The HIPAA audit checklist used by OCR during compliance investigations covers policies and procedures, training records, risk assessment documentation, sanctions records, breach notification files, and BAA records. Each of these document categories must be retained for a minimum of six years from the date of creation or the date it was last in effect, whichever is later.

Medical spas that cannot produce documentation during an OCR investigation face the same compliance exposure as organizations that never implemented the required safeguards. Documentation functions as evidence that the organization’s compliance program exists, was communicated to the workforce, and was enforced. The absence of records is not treated as proof that nothing went wrong. It is treated as evidence that the organization cannot demonstrate compliance.

An annual compliance review cycle provides a structured mechanism for updating policies to reflect regulatory changes, confirming that all workforce members have completed required training, reviewing audit logs and any incidents from the prior year, reassessing vendor relationships and BAA status, and confirming that the security risk assessment remains current. Medical spa operators who build compliance review into their operational calendar reduce the likelihood that a regulatory change or a staff turnover event will create an undetected gap in their compliance posture.

Medical spas operating across multiple locations must replicate the compliance program at each site. A policy maintained at a headquarters location does not automatically govern operations at a second or third location. Workforce training, designated compliance roles, and monitoring protocols must be implemented and documented at each facility where PHI is created, used, or maintained.

HIPAA common HIPAA violations in the medical spa sector are not materially different from those found in other small healthcare practices: impermissible disclosures, failure to execute BAAs, failure to train staff, failure to respond to patient access requests, and absence of a documented security risk assessment. Each of these failures is preventable through a structured compliance program built around the seven fundamental elements of effective compliance and adapted to the specific operational environment of a medical spa.

The post HIPAA Compliance for Medical Spas appeared first on The HIPAA Journal.

Why Medical Couriers Are Always Classified as HIPAA Business Associates

Other than when they are directly employed by a covered entity, medical couriers are always classified as a HIPAA business associate due to the nature of the work they are contracted to do and their “operational access” to Protected Health Information (PHI), even when access only consists of a visible name, reference number, or address.
Medical couriers play an important role in the healthcare system by transporting specimens, medications, lab results, and other items that support patient care. Because deliveries often involve sealed packages, it could be assumed that medical couriers do not qualify as business associates under the HIPAA conduit exception.
This exception applies to entities that transmit PHI on behalf of a covered entity or business associate without storing it and without having anything more than transient, incidental access to PHI. Examples include the US Postal Service, UPS, FedEx, and Internet Service Providers who simply act as channels through which information flows.

Why the Conduit Exception Does Not Apply to Medical Couriers

Medical couriers, by contrast, are contracted specifically to transport PHI. To fulfil the service they are contracted to provide, medical couriers routinely handle paperwork connected with specimens, read names on labels, sign or verify chain‑of‑custody forms, and confirm pickup and delivery details tied to specific patients.
Their access is not incidental, accidental, or transient, it is operational. Because of this, healthcare organizations, pharmacies, and labs must treat them as HIPAA business associates. That means medical couriers must sign Business Associate Agreements (BAAs) and comply with all applicable HIPAA standards. The same applies when an independent contractor is engaged by a business associate as a subcontractor.

When Access Only Consists of a Visible Name, Number, or Address

When access only consists of a visible name, reference number, or address, the visible information is still classified as PHI because these elements are references to individually identifiable health information being transported within the package. This means a visible name, reference number, or address on the outside of the package is part of the same designated record set as the information inside the package.
This distinction is important because information visible on the outside of the package must be protected with the same care as the information inside the package. It is for this reason that, other than when they are directly employed by a covered entity, medical couriers are always classified as HIPAA business associates, and must train their drivers, dispatchers, and customer service teams on all applicable HIPAA standards.

The post Why Medical Couriers Are Always Classified as HIPAA Business Associates appeared first on The HIPAA Journal.

What Is Healthcare-Adjacent Data?

Healthcare-adjacent data is any health‑related or health‑influenced information that falls outside HIPAA’s definition of Protected Health Information because it is not created, received, maintained, or transmitted by a covered entity or business associate, or because it is not processed for a HIPAA‑regulated activity.

As digital health tools, wearables, and AI‑driven services become more common, a growing amount of information sits near the edges of traditional healthcare. This information often looks like health data and can influence health decisions, yet it does not always qualify as Protected Health Information (PHI) under HIPAA.

Understanding the distinction between PHI and healthcare‑adjacent data has become essential for healthcare organizations, business associates, and third‑party service providers. They now operate in a regulatory environment shaped by overlapping federal and state privacy laws and by a digital ecosystem where data flows freely across clinical, consumer, and commercial systems.

How HIPAA Defines PHI — and What Falls Outside the Definition

HIPAA protects a specific category of individually identifiable health information that is created, received, maintained, or transmitted by a covered entity or business associate for a HIPAA‑regulated activity and that relates to an individual’s health, the provision of healthcare, or payment for healthcare. If any of these elements is missing, the information does not qualify as PHI and is not subject to the HIPAA Rules.

Healthcare‑adjacent data refers to health‑related or health‑influenced information that falls outside this definition. This includes employee health information maintained by a covered entity in its role as an employer, interactions with a hospital’s public social‑media pages, and identifiable information that has no healthcare component, such as data from cafeteria loyalty programs.

It also includes information collected by fitness trackers, consumer health apps, wellness programs, and other health‑related IoT devices. These data streams remain healthcare‑adjacent unless a third‑party service provider collects the information while acting as a business associate and transmits it to a covered entity for inclusion in the patient’s HIPAA‑protected medical record.

When Healthcare-Adjacent Data Becomes PHI

In many situations, healthcare‑adjacent data becomes PHI the moment a covered entity receives it. If a hospital imports information from a wearable or consumer health app, that data becomes PHI because it is now individually identifiable health information in the hands of a HIPAA‑regulated entity. Even non‑health information can take on PHI status if a covered entity stores it in the same designated record set as clinical or billing records.

For business associates, the analysis is more nuanced. When a business associate collects or receives healthcare‑adjacent data while performing services for a covered entity, the information becomes PHI. If the same type of data is collected for the business associate’s own purposes, outside the scope of services provided to a covered entity, it does not qualify as PHI and must be maintained separately.

The reverse scenario also matters. When an individual transfers PHI from a covered entity to a personal device or app, the copy retained by the covered entity remains PHI, but the version stored on the personal device is no longer protected by HIPAA. If the device or app vendor receives health data from the individual’s device, the vendor is not a business associate unless it has a formal business associate agreement with the covered entity that originally held the PHI.

How State Privacy Laws Treat Healthcare‑Adjacent Data

HIPAA is only one layer of the U.S. privacy landscape. Many state privacy laws exclude PHI from their scope but still regulate other types of health‑related data collected by the same organizations. This creates a situation in which a covered entity or business associate may be exempt from a state law for PHI yet fully subject to it for healthcare‑adjacent data.

California illustrates this clearly. The Confidentiality of Medical Information Act (CMIA) protects “medical information” held by providers and plans, while the California Consumer Privacy Act (CCPA/CPRA) exempts PHI but not other health‑related data such as website analytics, app telemetry, wellness‑program information, or health inferences used for marketing. A hospital’s EHR is exempt; its patient‑portal cookies and mobile‑app tracking data are not.

Washington’s My Health My Data Act goes even further. It exempts HIPAA PHI but regulates virtually any health‑related data collected by any entity, including hospitals, when the information is consumer‑generated, inferred, or collected outside treatment, payment, or healthcare operations. Other state privacy laws, including those in Colorado, Connecticut, and Virginia, follow a similar pattern: PHI is exempt, but non‑PHI health data is regulated as “sensitive data.”

This patchwork means that healthcare‑adjacent data often carries privacy obligations even when HIPAA does not apply.

Federal Rules That Affect Healthcare‑Adjacent Data and PHI

When healthcare-adjacent data is breached, the primary federal rule that may apply is the Health Breach Notification Rule. This Rule requires vendors of personal health records and similar services to notify the Federal Trade Commission and affected individuals if unencrypted, individually identifiable health information is exposed. The rule fills part of the regulatory gap for consumer‑generated health data that falls outside the scope of HIPAA.

HIPAA itself also contains provisions that affect how PHI may be shared in contexts that overlap with consumer‑facing technologies. Two important exceptions in the Privacy Rule allow covered entities to disclose PHI without patient authorization.

The first, found in 45 CFR §164.512(b)(1), permits disclosures to FDA‑regulated device vendors for activities related to the quality, safety, or effectiveness of an FDA‑regulated product. This includes personal health devices that transmit data to AI‑driven healthcare solutions.

The second exception, in 45 CFR §164.512(i)(1), allows PHI to be disclosed for preparatory research without de‑identification if the disclosure is approved by an Institutional Review Board or Privacy Board. In these cases, the PHI must remain with the covered entity and may only be used for preparatory activities such as training a supervised learning algorithm.

Together, these federal and state frameworks create a complex environment in which PHI, healthcare‑adjacent data, and consumer‑generated health information may each be subject to different obligations depending on who holds the data, why it was collected, and how it is used.

Must Covered Entities Combine All Health Information Into HIPAA‑Protected Record Sets?

Some organizations believe that covered entities are required to combine all health‑related data into HIPAA‑protected designated record sets to simplify HIPAA compliance. In practice, the picture is mixed.

HIPAA does not require covered entities to consolidate all health‑related data into a designated record set (DRS). A DRS is defined narrowly. It includes medical records, billing records, and other records used to make decisions about individuals. Website analytics, marketing data, app telemetry, and consumer‑generated data do not belong in a DRS unless the covered entity intentionally places them there.

Some organizations do consolidate data to reduce ambiguity and apply HIPAA‑level safeguards universally. This approach simplifies HIPAA training and reduces the risk of misclassification. However, many organizations intentionally keep systems separate because adding data to a DRS increases HIPAA obligations, complicates vendor relationships, and may conflict with state privacy requirements. Marketing platforms, mobile apps, and analytics tools often operate outside HIPAA, and vendors may not sign Business Associate Agreements for non‑clinical data.

The trend is toward hybrid models in which organizations apply HIPAA‑like protections to all health‑related data while still maintaining clear boundaries between PHI and non‑PHI systems for regulatory and operational reasons.

Why Understanding What Healthcare-Adjacent Data is Matters

As healthcare delivery expands beyond traditional clinical settings, more data flows through consumer devices, apps, and AI‑enabled tools that sit outside HIPAA’s boundaries. This creates regulatory gaps, new obligations for vendors, and new risks for covered entities receiving external data.

Understanding what qualifies as PHI, and what qualifies as healthcare-adjacent data, is essential for designing compliant workflows, evaluating vendor relationships, and protecting individuals whose health information now moves across environments both regulated and unregulated by HIPAA.

The post What Is Healthcare-Adjacent Data? appeared first on The HIPAA Journal.

Is Wix HIPAA Compliant?

When this article was first published in early 2025, Wix was not a HIPAA-compliant service; however, the company has since implemented comprehensive measures to allow its platform to be used by HIPAA-regulated entities, and the company is prepared to sign a business associate agreement with HIPAA-regulated entities.

HIPAA Compliant Email Services

Wix is a service that helps businesses in all industries easily design, build, and host websites. Depending on the type of subscription, customers’ websites can include appointment scheduling software, e-commerce platforms, and loyalty programs. The service scores highly for performance, reliability, and security, and is certified PCI DSS and ISO 27001 compliant.

With regard to collecting data from website visitors, Wix enables customers to comply with the California Consumer Privacy Act (CCPA) and other state privacy laws that require an affirmative opt-in before data can be used for marketing purposes.

When it comes to collecting Protected Health Information (PHI) from website visitors, HIPAA-regulated entities must ensure that they use a platform that incorporates all of the necessary safeguards to ensure the confidentiality, integrity, and availability of PHI, and a regulated entity must enter into a business associate agreement (BAA) with the platform provider.

Wix has now incorporated a comprehensive range of measures to allow its platform to be used by HIPAA-regulated entities and provides both the tools and contractual safeguards to support HIPAA compliance. Provided customers have the appropriate Wix plan, take certain steps to make their Wix website HIPAA-compliant, and only use Wix’s HIPAA-designated apps and services, then Wix websites can be HIPAA-compliant.

How Does Wix Comply with HIPAA?

Customers with certain Wix plans (supported Premium or Studio plans) can activate a PHI protection feature from the Compliance, Privacy & Cookies section of their site dashboard. Activating this feature provides enhanced administrative, physical, and technical safeguards. These include encryption of ePHI at rest and in transit, access controls, audit logging, and the automatic restriction of non-HIPAA-compliant features and applications.

After activating this feature, users can execute a formal BAA with Wix. The BAA establishes Wix’s obligations under the HIPAA Rules. Wix agrees to comply with the permitted and required uses and disclosures of PHI, maintain appropriate safeguards, comply with data access, amendment, and accounting requirements, and the breach reporting requirements of the HIPAA Breach Notification Rule.

A HIPAA-regulated entity may request a copy of all PHI data on the site and submit a request to have the information securely and permanently deleted. Wix has published resources on its website to help HIPAA-regulated entities ensure HIPAA compliance when using its services:  Wix Services and HIPAA and HIPAA Compliance for Your Wix Site.

In order to comply with HIPAA, users must ensure that they only use specific services and apps on their website that have been approved for HIPAA use. Wix has curated a collection of apps in the Wix App Market and explicitly designates which apps and services support HIPAA compliance, allowing regulated entities to clearly identify which apps and services may be used to create, receive, maintain, or transmit ePHI.

What this Means for HIPAA Covered Entities and Business Associates

HIPAA-covered entities and business associates can use a website built on Wix to collect non-health information such as names, phone numbers, and email addresses. This is because information of this type is not considered PHI when it is not maintained in the same designated record set as individually identifiable health information.

Provided that forms are limited in the information they collect, that the appointment scheduling software does not reveal the nature of treatment, and that payment systems are just used for payment processing, covered entities and business associates will not be in violation of HIPAA for creating, receiving, maintaining, or transmitting non-health information via the service.

Before a website built on Wix is used to collect PHI, users must configure the options correctly, enter into a BAA with Wix, and only use apps and services that support HIPAA compliance. If those steps are taken, Wix websites are HIPAA compliant. Further, Wix’s HIPAA compliance features align with the international healthcare information security standard ISO 27799, to support healthcare providers in meeting strict data protection and security requirements, such as the EU’s General Data Protection Regulation (GDPR).

It should be noted that while a company can implement all of the necessary measures to support HIPAA-compliance, including signing a business associate agreement, it is up to each regulated entity to ensure that the product or service is used correctly.

The post Is Wix HIPAA Compliant? appeared first on The HIPAA Journal.

HIPAA Violation Fines

HIPAA violation fines can be issued by the Department of Health and Human Services’ Office for Civil Rights (OCR) and state attorneys general for failing to comply with HIPAA regulations. Ten Most Common HIPAA ViolationsIn this article, we provide a detailed explanation of HIPAA violation fines that have been imposed on HIPAA-regulated entities found to have violated the HIPAA Rules.

You can also use the article in conjunction with our free HIPAA Violations Checklist to understand what is required to ensure full compliance. Please use the form on this page to arrange for your copy.

The Majority Of HIPAA Violation Fines are from Settlements

In the majority of cases, covered entities and business associates accept that there have been potential failures to comply with certain elements of HIPAA Rules, a settlement amount is agreed, and the case is resolved with no admission of liability. In addition to the settlement, a corrective action plan is issued to address the HIPAA failures. HIPAA-covered entities and business associates may disagree with the findings of the investigation and challenge the decision to impose a penalty. In such cases, they are given the opportunity to provide evidence to support a waiver of the penalty. If they are unsuccessful, a civil monetary penalty will be imposed. The civil monetary penalty will be more than the penalty they would pay if they settled the alleged violations. OCR cannot impose a corrective action plan when a civil monetary penalty is imposed.

While OCR issues fines for HIPAA violations, attorneys general often choose to pursue financial penalties against HIPAA-regulated entities under state laws rather than HIPAA. Actions for violations of state laws tend to be easier to win, and the penalty structure at the state level may even allow higher financial penalties to be issued. Only a handful of states have exercised their right under HIPAA/HITECH to file lawsuits to pursue financial penalties for violations of HIPAA Rules against HIPAA-covered entities and their business associates, although all states have participated in at least one multi-state action.

Penalty Structure for HIPAA Violations

The penalty amounts are adjusted annually to account for the cost-of-living increases. The last update, published in the Federal Register on January 28, 2026, applies to all financial penalties imposed after November 2, 2015.  The inflation multiplier for 2025 set by the Office of Management and Budget (OMB) was 1.02598. While OMB states that the multiplier should be applied no later than January 15, 2025, the HHS determines that an exception applies, and typically applies the annual increases much later. For instance, the 2025 inflation multiplier was not applied for more than a year.  The current penalties for HIPAA violations in 2026 are detailed in the table below:

Penalty Tier Level of Culpability Minimum Penalty per Violation Maximum Penalty per Violation Annual Penalty Limit 
Tier 1 Reasonable Efforts $145 $73,011 $2,190,294
Tier 2 Lack of Oversight $1,461 $73,011 $2,190,294
Tier 3 Neglect – Rectified within 30 days $14,602 $73,011 $2,190,294
Tier 4 Neglect – Not Rectified within 30 days $73,011 $2,190,294 $2,190,294

*Table last updated on January 28, 2026, and includes the cost-of-living adjustment multiplier for 2025 (1.02598). 

While the above table shows the official penalty amounts for HIPAA violations, OCR issued a Notice of Enforcement Discretion in April 2019 stating the annual penalty limits in three of the penalty tiers would be reduced following a reexamination of the language of the HITECH Act. The cap on the annual penalty limit was changed to $25,000 for tier 1, $100,000 for tier 2, and $250,000 for tier 3. The maximum annual penalty for Tier 4 remains unchanged at $1,500,000. These caps are also subject to inflation increases. The table below was calculated by the HIPAA Journal, factoring in the annual inflation increases and applying OCR’s Notice of Enforcement Discretion.

The maximum penalty per violation in tier 1 is higher than the annual cap for that tier, as the notice of enforcement discretion only reduced the annual penalty cap, not the maximum penalty for a HIPAA violation. This discrepancy could be addressed when the new reinterpreted penalty structure is formally adopted through future rulemaking; however, the Notice of Enforcement Discretion will remain in effect indefinitely, although it is not legally binding and OCR can choose to rescind that Notice of Enforcement Discretion at any point. Further rulemaking to officially adopt the reinterpreted requirements of the HITECH Act is unlikely, as OCR is pushing to have Congress increase the penalties for HIPAA violations to make them a more effective deterrent.

Annual Penalty Limit  Minimum Penalty per Violation Maximum Penalty per Violation Annual Penalty Cap
Tier 1 Lack of Knowledge $145 $36,505.50 $36,505.50
Tier 2 Reasonable Cause  $1,461 $73,011 $146,053
Tier 3 Willful Neglect $14,602 $73,011 $365,052
Tier 4 Willful neglect (not corrected within 30 days $73,011 $2,190,294 $2,190,294

*Table last updated on January 28, 2026. 

State attorneys general can issue fines for HIPAA violations up to a maximum of $25,000 per violation category, per year. These penalties are also subject to annual adjustments for inflation.

Listed below are the HIPAA violation fines and settlements imposed by the HHS’ Office for Civil Rights since the HIPAA Enforcement Rule was signed into law, and enforcement actions by State Attorneys General for violations of the HIPAA Rules and equivalent state laws.

HIPAA violation penalties 2009-2026

Funds raised from OCR HIPAA fines and settlements 2009-2026

2026 HIPAA Violation Fines and Settlements

The HHS’ Office for Civil Rights is continuing with its HIPAA right of access and risk analysis enforcement initiatives, and commenced the enforcement of the Part 2 regulations under its newly delegated responsibility on February 16, 2026. The OCR Director has confirmed that in 2026, OCR will expand its risk analysis enforcement initiative to also include risk management.

Year Entity Amount Settlement/CMP Reason
2026 Spencer Gifts LLC Flexible Benefits and Welfare Benefit Plans $450,000 Settlement Risk analysis failure and a lack of HIPAA Privacy, Security & Breach Notification Rule Policies and procedures
2026 Assured Imaging Affiliated Covered Entities $375,000 Settlement Risk analysis failure, impermissible disclosure of the ePHI of 244,813 individuals
2026 Regional Women’s Health Group, dba Axia Women’s Health $320,000 Settlement Risk analysis failure
2026 Consociate Health $225,000 Settlement Risk analysis failure
2026 Star Group, L.P. Health Benefits Plan $245,000 Settlement Risk analysis failure and impermissible disclosure of the ePHI of 9,316 individuals.
2026 MMG Fusion $10,000 Settlement Risk analysis failure, breach notification failure, and an impermissible disclosure of the PHI of 15 million patients.
2026 Top of the World Ranch Treatment Center $103,000 Settlement Risk analysis failure

2025 HIPAA Violation Fines and Settlements

Year Entity Amount Settlement/CMP Reason
2025 Concentra Inc. $112,500 Settlement HIPAA Right of Access violation
2025 Cadia Healthcare Facilities $182,000 Settlement Social media disclosure without authorization and Breach Notification Rule failure
2025 Syracuse ASC, dba Specialty Surgery Center of Central New York $250,000 Settlement Risk analysis failure; untimely data breach notifications to the HHS Secretary & individuals
2025 Deer Oaks – The Behavioral Health Solution $225,000 Settlement Risk analysis failure; impermissible disclosure of ePHI
2025 Comstar LLC $75,000 Settlement Risk analysis failure
2025 BayCare Health System $800,000 Settlement Information access management (minimum necessary standard), risk management, information system activity review
2025 Vision Upright MRI $5,000 Settlement HIPAA Risk Analysis violation, HIPAA breach notification violation
2025 Comprehensive Neurology $25,000 Settlement HIPAA Risk Analysis violation
2025 PIH Health $600,000 Settlement HIPAA Risk Analysis violation, impermissible disclosure of the ePHI of 189,763 individuals, failure to issue a media breach notice, failure to issue timely breach notifications to the HHS, and the affected patients
2025 Guam Memorial Hospital Authority $25,000 Settlement HIPAA Risk Analysis violation
2025 Northeast Radiology $350,000 Settlement HIPAA Risk Analysis violation
2025 Health Fitness Corporation $227,816 Settlement HIPAA Risk Analysis violation
2025 Oregon Health & Science University $200,000 Civil Monetary Penalty Violation of the HIPAA Right of Access
2025 Warby Parker, Inc. $1,500,000 Civil Monetary Penalty Violation of the HIPAA Security Rule: Risk analysis, risk management, and monitoring activity in information systems containing ePHI
2024 Northeast Surgical Group $10,000 Settlement Failure to conduct a HIPAA-compliant risk analysis
2024 Memorial Health System $60,000 Settlement Violation of the HIPAA Right of Access
2024 Solara Medical Supplies $3,000,000 Settlement Risk analysis failure, risk management failure, breach notification failure, and the impermissible disclosure of the ePHI of 114,007 and 1,531 patients.
2024 USR Holdings $337,750 Settlement Risk analysis failure, failure to record activity in information systems, lack of procedures for creating and maintaining retrievable exact copies of ePHI, and the impermissible disclosure of the ePHI of 2,903 individuals
2024 Virtual Private Network Solutions $90,000 Settlement Risk analysis failure
2024 Elgon Information Systems $80,000 Settlement Risk analysis failure

2024 HIPAA Violation Fines and Settlements

The OCR Director provided an end-of-year update on December 31, 2024, and confirmed that 22 investigations of data breaches and complaints resulted in civil monetary penalties or settlements in 2024, making it one of the busiest years for HIPAA enforcement; however, only 16 of those enforcement actions were announced in 2024. The remaining six were announced by OCR in early January 2025, before the administration change.

Year Entity Amount Settlement/CMP Reason
2024 Inmediata Health Group $250,000 Settlement Risk analysis failure, failure to monitor activity in information systems, impermissible disclosure of the ePHI of 1,565,338 individuals
2024 Children’s Hospital Colorado Health System $548,265 Civil Monetary Penalty Failure to provide HIPAA Privacy Rule training to 6,666 workforce members; failure to conduct a thorough and accurate risk analysis; impermissible disclosure of ePHI of 10,840 individuals
2024 Holy Redeemer Family Medicine $35,581 Settlement Impermissible disclosure of a patient’s medical records
2024 Rio Hondo Community Mental Health Center $100,000 Civil Monetary Penalty Failure to provide timely access to medical records (7 months)
2024 Bryan County Ambulance Authority $90,000 Settlement Never conducted a risk analysis
2024 Plastic Surgery Associates of South Dakota $500,000 Settlement Risk analysis failure; risk management failure; no analysis of logs of system activity; no policies for dealing with a security incident
2024 Gums Dental Care $70,000 Civil Monetary Penalty Failure to provide timely access to medical records
2024 Providence Medical Institute $240,000 Civil Monetary Penalty Failure to only allow authorized persons or software programs access to ePHI; lack of a business associate agreement
2024 Cascade Eye and Skin Centers $250,000 Settlement Risk analysis failure; failure to review records of system activity
2024 American Medical Response $115,200 Civil Monetary Penalty Failure to provide timely access to medical records (370 days)
2024 Heritage Valley Health System $950,000 Settlement Failure to conduct a risk analysis, lack of policies/procedures for responding to an emergency, and a lack of technical policies and procedures for restricting access to systems containing ePHI.
2024 Essex Residential Care (Hackensack Meridian Health, West Caldwell Care Center) $100,000 Civil Monetary Penalty Failure to provide timely access to medical records.
2024 Phoenix Healthcare $35,000 Settlement Failure to provide timely access to medical records.
2024 Green Ridge Behavioral Health $40,000 Settlement Failure to conduct a comprehensive risk analysis, failure to reduce risks to ePHI, lack of policies and procedures for monitoring activity in information systems containing ePHI, and an impermissible disclosure of the ePHI of 14,000 individuals.
2024 Montefiore Medical Center $4,750,000 Settlement Failure to conduct a comprehensive risk analysis, failure to implement procedures to regularly review records of information system activity, and the failure to implement hardware, software, and/or procedural mechanisms that record and examine activity in all information systems that contain or use ePHI.

2023 HIPAA Violation Fines and Settlements

Year Entity Amount Settlement/CMP Reason
2023 Optum Medical Care of New Jersey $160,000 Settlement Failure to provide 6 patients with timely access to their medical records.
2023 Lafourche Medical Group $480,000 Settlement No risk analysis prior to a  2021 security breach, and no procedures to regularly review logs of system activity prior to the breach.
2023 St. Joseph’s Medical Center $80,000 Settlement A reporter was allowed access to 3 patients and their clinical information without first obtaining authorizations from the patients.
2023 Doctors’ Management Services $100,000 Settlement Risk analysis, review records of system activity, reasonable and appropriate policies/procedures to comply with the HIPAA Security Rule, and an impermissible disclosure of the PHI of 206,695 individuals
2023 L.A. Care Health Plan $1,300,000 Settlement Risk analysis, insufficient security measures, insufficient reviews of records of information system activity, insufficient evaluations in response to environmental/operational changes, insufficient recording and examination of activity in information systems, impermissible disclosure of the ePHI of 1,498 individuals.
2023 UnitedHealthcare $80,000 Settlement HIPAA Right of Access Failure
2023 iHealth Solutions, dba Advantum Health $75,000 Settlement Failure to secure a server, resulting in the theft of ePHI. Risk analysis failure and the impermissible disclosure of the ePHI of 267 individuals.
2023 Yakima Valley Memorial Hospital $240,000 Settlement 23 security guards in the emergency department snooped on the medical records of 419 patients. OCR determined there was a lack of HIPAA policies and procedures.
2023 Manasa Health Center, LLC $30,000 Settlement Impermissible disclosure of the PHI of 4 individuals in response to negative Google Reviews. Failure to implement HIPAA Privacy and Breach Notification Rule policies and procedures
2023 MedEvolve Inc. $350,000 Settlement Impermissible disclosure of the PHI of 230,572 individuals. No BAA with a subcontractor, incomplete risk analysis
2023 David Mente, MA, LPC $15,000 Settlement HIPAA Right of Access failure
2023 Banner Health $1,250,000 Settlement Risk analysis, reviews of system activity, verification of identity for access to PHI, and lack of technical safeguards
2023 Life Hope Labs, LLC $16,500 Settlement HIPAA Right of Access failure

2022 HIPAA Violation Fines and Settlements

Year Entity Amount Settlement/CMP Reason
2022 Health Specialists of Central Florida Inc $20,000 Settlement HIPAA Right of Access failure
2022 New Vision Dental $23,000 Settlement Impermissible PHI disclosure, notice of privacy practices, and releasing PHI on social media
2022 Great Expressions Dental Center of Georgia, P.C. $80,000 Settlement HIPAA Right of Access failure (delay/fee)
2022 Family Dental Care, P.C. $30,000 Settlement HIPAA Right of Access failure
2022 B. Steven L. Hardy, D.D.S., LTD, dba Paradise Family Dental $25,000 Settlement HIPAA Right of Access failure
2022 New England Dermatology and Laser Center $300,640 Settlement Improper disposal of PHI, failure to maintain appropriate safeguards
2022 ACPM Podiatry $100,000 Civil Monetary Penalty HIPAA Right of Access failure
2022 Memorial Hermann Health System $240,000 Settlement HIPAA Right of Access failure
2022 Southwest Surgical Associates $65,000 Settlement HIPAA Right of Access failure
2022 Hillcrest Nursing and Rehabilitation $55,000 Settlement HIPAA Right of Access failure
2022 MelroseWakefield Healthcare $55,000 Settlement HIPAA Right of Access failure
2022 Erie County Medical Center Corporation $50,000 Settlement HIPAA Right of Access failure
2022 Fallbrook Family Health Center $30,000 Settlement HIPAA Right of Access failure
2022 Associated Retina Specialists $22,500 Settlement HIPAA Right of Access failure
2022 Coastal Ear, Nose, and Throat $20,000 Settlement HIPAA Right of Access failure
2022 Lawrence Bell, Jr. D.D.S $5,000 Settlement HIPAA Right of Access failure
2022 Danbury Psychiatric Consultants $3,500 Settlement HIPAA Right of Access failure
2022 Oklahoma State University – Center for Health Sciences $875,000 Settlement Risk analysis, security incident response and reporting, evaluation, audit controls, breach notifications, & the impermissible disclosure of the PHI of 279,865 individuals
2022 Dr. Brockley $30,000 Settlement HIPAA Right of Access
2022 Jacob & Associates $28,000 Settlement HIPAA Right of Access, notice of privacy practices, HIPAA Privacy Officer
2022 Dr. U. Phillip Igbinadolor, D.M.D. & Associates, P.A., $50,000 Civil Monetary Penalty Impermissible disclosure on social media
2022 Northcutt Dental-Fairhope $62,500 Settlement Impermissible disclosure for marketing, notice of privacy practices, HIPAA Privacy Officer

2021 HIPAA Violation Fines and Settlements

Year Entity Amount Settlement/CMP Reason
2021 Advanced Spine & Pain Management $32,150 Settlement HIPAA Right of Access failure
2021 Denver Retina Center $30,000 Settlement HIPAA Right of Access failure
2021 Dr. Robert Glaser $100,000 Civil Monetary Penalty HIPAA Right of Access failure
2021 Rainrock Treatment Center LLC (dba monte Nido Rainrock) $160,000 Settlement HIPAA Right of Access failure
2021 Wake Health Medical Group $10,000 Settlement HIPAA Right of Access failure
2021 Children’s Hospital & Medical Center $80,000 Settlement HIPAA Right of Access failure
2021 The Diabetes, Endocrinology & Lipidology Center, Inc. $5,000 Settlement HIPAA Right of Access failure
2021 AEON Clinical Laboratories (Peachstate) $25,000 Settlement HIPAA Security Rule failures (risk assessment, risk management, audit controls, and lack of documentation of HIPAA Security Rule policies and procedures)
2021 Village Plastic Surgery $30,000 Settlement HIPAA Right of Access failure
2021 Arbour Hospital $65,000 Settlement HIPAA Right of Access failure
2021 Sharpe Healthcare $70,000 Settlement HIPAA Right of Access failure
2021 Renown Health $75,000 Settlement HIPAA Right of Access failure
2021 Excellus Health Plan $5,100,000 Settlement Multiple violations: Risk analysis failure, risk management failure, lack of information system activity reviews, lack of technical policies to prevent unauthorized ePHI access, and a breach of 9,358,891 records.
2021 Banner Health $200,000 Settlement HIPAA Right of Access failure

2020 HIPAA Violation Fines and Settlements

Year Entity Amount Settlement/CMP Reason
2020 Peter Wrobel, M.D., P.C., dba Elite Primary Care $36,000 Settlement HIPAA Right of Access failure
2020 University of Cincinnati Medical Center $65,000 Settlement HIPAA Right of Access failure
2020 Dr. Rajendra Bhayani $15,000 Settlement HIPAA Right of Access failure
2020 Riverside Psychiatric Medical Group $25,000 Settlement HIPAA Right of Access failure
2020 City of New Haven, CT $202,400 Settlement Failure to terminate access rights, risk analysis failure, failure to implement Privacy Rule policies, failure to issue unique IDs, impermissible disclosure of the PHI of 498 individuals
2020 Aetna $1,000,000 Settlement Failure to conduct an evaluation in response to environmental or operational changes affecting ePHI security, identity check failure, minimum necessary information failure, lack of admin, technical, and physical safeguards
2020 NY Spine $100,000 Settlement HIPAA Right of Access failure
2020 Dignity Health, dba St. Joseph’s Hospital and Medical Center $160,000 Settlement HIPAA Right of Access failure
2020 Premera Blue Cross $6,850,000 Settlement Risk assessment failure, risk management failure, insufficient hardware, and software controls,
2020 CHSPSC LLC $2,300,000 Settlement Risk analysis failure, failure to implement information system activity reviews, security incident procedure failure, and insufficient access controls.
2020 Athens Orthopedic Clinic PA $1,500,000 Settlement Failures to conduct a risk analysis, risk management failure, lack of audit controls, no HIPAA policies and procedures, lack of business associate agreements, and no HIPAA Privacy Rule training to the workforce.
2020 Housing Works, Inc. $38,000 Settlement HIPAA Right of Access failure
2020 All Inclusive Medical Services, Inc. $15,000 Settlement HIPAA Right of Access failure
2020 Beth Israel Lahey Health Behavioral Services $70,000 Settlement HIPAA Right of Access failure
2020 King MD $3,500 Settlement HIPAA Right of Access failure
2020 Wise Psychiatry, PC $10,000 Settlement HIPAA Right of Access failure
2020 Lifespan Health System Affiliated Covered Entity $1,040,000 Settlement Lack of encryption, device and media controls, and business associate agreement failures.
2020 Metropolitan Community Health Services dba Agape Health Services $25,000 Settlement Systemic noncompliance with the HIPAA Security Rule
2020 Steven A. Porter, M.D $100,000 Settlement Risk analysis and risk management failures

2019 HIPAA Violation Fines and Settlements

Year Covered Entity Amount Settlement/CMP Reason
2019 West Georgia Ambulance $65,000 Settlement Risk analysis failure, no security awareness training program, and a failure to implement HIPAA Security Rule policies and procedures.
2019 Korunda Medical, LLC $85,000 Settlement HIPAA Right of Access failure.
2019 Sentara Hospitals $2,175,000 Settlement Breach notification failure; business associate agreement failure
2019 University of Rochester Medical Center $3,000,000 Settlement Loss of flash drive/laptop; no encryption; risk analysis failure; risk management failure; lack of device media controls.
2019 Elite Dental Associates $10,000 Settlement Social media disclosure, notice of privacy practices. and impermissible PHI disclosure.
2019 Bayfront Health St Petersburg $85,000 Settlement HIPAA Right of Access failure
2019 Medical Informatics Engineering $100,000 Settlement Risk analysis failure; impermissible disclosure of 3.5 million records
2019 Touchstone Medical Imaging $3,000,000 Settlement No BAAs; insufficient access rights; risk analysis failure; failure to respond to a security incident; breach notification failure; media notification failure; impermissible disclosure of 307,839 individuals’ PHI.
2019 Texas Department of Aging and Disability Services $1,600,000 Civil Monetary Penalty Risk analysis failure; access control failure; information system activity monitoring failure; impermissible disclosure of 6,617 patients’ ePHI
2019 Jackson Health System $2,154,000 Civil Monetary Penalty Multiple Privacy Rule, Security Rule, and Breach Notification Rule violations

2018 HIPAA Violation Fines and Settlements

Year Covered Entity Amount Settlement/CMP Reason
2018 Fresenius Medical Care North America $3,500,000 Settlement Risk analysis failures, impermissible disclosure of ePHI; Lack of policies covering electronic devices; Lack of encryption; Insufficient security policies; Insufficient physical safeguards
2018 Filefax, Inc. $100,000 Settlement Impermissible disclosure of PHI
2018 University of Texas MD Anderson Cancer Center $4,348,000 Civil Monetary Penalty Impermissible disclosure of ePHI; No Encryption
2018 Massachusetts General Hospital $515,000 Settlement Filming patients without consent
2018 Brigham and Women’s Hospital $384,000 Settlement Filming patients without consent
2018 Boston Medical Center $100,000 Settlement Filming patients without consent
2018 Anthem Inc $16,000,000 Settlement Risk Analysis failures; Insufficient reviews of system activity; Failure related to response to a detected breach; Insufficient technical controls to prevent unauthorized ePHI access
2018 Allergy Associates of Hartford $125,000 Settlement PHI disclosure to a reporter; No sanctions against employees
2018 Advanced Care Hospitalists $500,000 Settlement Impermissible PHI Disclosure; No BAA; Insufficient security measures; No HIPAA compliance efforts prior to April 1, 2014
2018 Pagosa Springs Medical Center $111,400 Settlement Failure to terminate employee access; No BAA
2018 Cottage Health $3,000,000 Settlement Risk analysis failure; Risk management failure; No BAA

2017 HIPAA Violation Fines and Settlements

Year Covered Entity Amount Settlement/CMP Reason
2017 21st Century Oncology $2,300,000 Settlement Multiple HIPAA Violations
2017 Memorial Hermann Health System $2,400,000 Settlement Careless Handling of PHI
2017 St. Luke’s-Roosevelt Hospital Center Inc. $387,000 Settlement Unauthorized Disclosure of PHI
2017 The Center for Children’s Digestive Health $31,000 Settlement Lack of a Business Associate Agreement
2017 Cardionet $2,500,000 Settlement Impermissible Disclosure of PHI
2017 Metro Community Provider Network $400,000 Settlement Lack of Security Management Process
2017 Memorial Healthcare System $5,500,000 Settlement Insufficient ePHI Access Controls
2017 Children’s Medical Center of Dallas $3,200,000 Civil Monetary Penalty Impermissible Disclosure of ePHI
2017 MAPFRE Life Insurance Company of Puerto Rico $2,200,000 Settlement Impermissible Disclosure of ePHI
2017 Presense Health $475,000 Settlement Delayed Breach Notifications

2016 HIPAA Violation Fines and Settlements

Year Covered Entity Amount Settlement/CMP Reason
2016 University of Massachusetts Amherst (UMass) $650,000 Settlement Failure to Manage Security Risks
2016 St. Joseph Health $2,140,500 Settlement Failure to Conduct Risk Analysis
2016 Care New England Health System $400,000 Settlement Lack of a Business Associate Agreement
2016 Advocate Health Care Network $5,550,000 Settlement Multiple HIPAA Violations
2016 University of Mississippi Medical Center $2,750,000 Settlement Multiple HIPAA Violations
2016 Oregon Health & Science University $2,700,000 Settlement Lack of a Business Associate Agreement
2016 Catholic Health Care Services of the Archdiocese of Philadelphia $650,000 Settlement Failure to Safeguard ePHI
2016 New York Presbyterian Hospital $2,200,000 Settlement Filming Patients without Authorization
2016 Raleigh Orthopaedic Clinic, P.A. of North Carolina $750,000 Settlement Lack of Business Associate Agreement
2016 Feinstein Institute for Medical Research $3,900,000 Settlement Impermissible Disclosure of PHI
2016 North Memorial Health Care of Minnesota $1,550,000 Settlement Lack of a Business Associate Agreement
2016 Complete P.T., Pool & Land Physical Therapy, Inc. $25,000 Settlement Impermissible Disclosure of PHI
2016 Lincare, Inc. $239,800 Civil Monetary Penalty Failure to Safeguard PHI

2015 HIPAA Violation Fines and Settlements

Year Covered Entity Amount Settlement/CMP Reason
2015 University of Washington Medicine $750,000 Settlement Failure to Conduct Risk Analysis
2015 Triple S Management Corporation $3,500,000 Settlement Multiple HIPAA Violations
2015 Lahey Hospital and Medical Center $850,000 Settlement Multiple HIPAA Violations
2015 Cancer Care Group, P.C. $750,000 Settlement Failure to Conduct Risk Analysis
2015 St. Elizabeth’s Medical Center $218,400 Settlement Multiple HIPAA Violations
2015 Cornell Prescription Pharmacy $125,000 Settlement Improper Disposal of PHI

2014 HIPAA Violation Fines and Settlements

Year Covered Entity Amount Settlement/CMP Reason
2014 Anchorage Community Mental Health Services $150,000 Settlement Failure to Manage Risks to ePHI
2014 Parkview Health System, Inc. $800,000 Settlement Failure to Safeguard PHI
2014 New York and Presbyterian Hospital and Columbia University $4,800,000 Settlement Failure to Conduct Risk Analysis
2014 QCA Health Plan, Inc., of Arkansas $250,000 Settlement Failure to Safeguard ePHI
2014 Concentra Health Services $1,725,220 Settlement Failure to Safeguard ePHI
2014 Skagit County, Washington $215,000 Settlement Failure to Safeguard ePHI

2013 HIPAA Violation Fines and Settlements

Year Covered Entity Amount Settlement/CMP Reason
2013 Adult & Pediatric Dermatology, P.C. $150,000 Settlement Failure to Safeguard ePHI
2013 Affinity Health Plan, Inc. $1,215,780 Settlement Failure to Permanently Erase ePHI
2013 WellPoint $1,700,000 Settlement Failure to Safeguard ePHI
2013 Shasta Regional Medical Center $275,000 Settlement Disclosure of PHI Without Patient Consent
2013 Idaho State University $400,000 Settlement Failure to Safeguard ePHI

2012 HIPAA Violation Fines and Settlements

Year Covered Entity Amount Settlement/CMP Reason
2012 The Hospice of Northern Idaho $50,000 Settlement Theft of an Unencrypted Laptop
2012 Massachusetts Eye and Ear Infirmary and Massachusetts Eye and Ear Associates, Inc. $1,500,000 Settlement Multiple HIPAA Violations
2012 Alaska DHSS $1,700,000 Settlement Failure to Perform Risk Analysis/Risk Management Failures
2012 Phoenix Cardiac Surgery $100,000 Settlement Lack of HIPAA Safeguards
2012 Blue Cross Blue Shield of Tennessee $1,500,000 Settlement Failure to Implement Appropriate Administrative Safeguards

2011 HIPAA Violation Fines and Settlements

Year Covered Entity Amount Settlement/CMP Reason
2011 University of California at Los Angeles Health System $865,500 Settlement Failure to Restrict Access to Medical Records
2011 General Hospital Corp. & Massachusetts General Physicians Organization Inc. $1,000,000 Settlement Failure to Safeguard PHI
2011 Cignet Health of Prince George’s County $4,300,000 Civil Monetary Penalty Denying Patients Access to Medical Records

2010 HIPAA Violation Fines and Settlements

Year Covered Entity Amount Settlement/CMP Reason
2010 Management Services Organization Washington Inc. $35,000 Settlement Risk Analysis Failures / Insufficient Security Measures
2010 Rite Aid Corporation $1,000,000 Settlement Multiple HIPAA Violations

2009 HIPAA Violation Fines and Settlements

Year Covered Entity Amount Settlement/CMP Reason
2009 CVS Pharmacy Inc. $2,250,000 Settlement Multiple HIPAA Violations

2008 HIPAA Violation Fines and Settlements

Year Covered Entity Amount Settlement/CMP Reason
2008 Providence Health & Services $100,000 Settlement Failure to Implement Appropriate Administrative Safeguards

State Attorneys General HIPAA Fines and Settlements

State attorneys general have the authority to impose financial penalties for HIPAA violations, but oftentimes, while HIPAA has been violated, fines are imposed for violations of state laws. The list below includes civil monetary penalties and settlements that have been imposed for HIPAA violations and/or violations of equivalent state laws.

Cases have been included if there have been potential violations of HIPAA Rules, even if the financial penalty was issued for violations of state laws.

Year State Entity Amount Individuals affected Reason
2026 Massachusetts & Connecticut Comstar LLC $515,000 585,621 individuals (326,426 Massachusetts residents & 22,829 Connecticut residents) Violations of the HIPAA Security Rule and the Massachusetts Data Security Regulations
2025 New York Orthopedics NY LLP $500,000 656,086 Violations of the HIPAA Security Rule and state healthcare privacy and security laws
2024 Indiana Westend Dental $350,000 Unknown Violations of the HIPAA Privacy, Security & Breach Notification Rules; Indiana Disclosure of Security Breach Act; Indiana Deceptive Consumer Sales Act
2024 New York HealthAlliance $1,400,000 ($850,000 suspended) 242,641 Violations of New York Business and Executive Law
2024 New York Albany ENT & Allergy Services $1,000,000 ($500,000 suspended); $2.24M investment in cybersecurity 213,935 Violations of New York Business and Executive Law
2024 New York, New Jersey, Connecticut Enzo Biochem/Enzo Clinical Labs $4,500,000 2,400,000 Violations of 12 provisions of the HIPAA Security Rule and a violation of New York General Business Law
2024 Washington Allure Esthetic $5,000,000 21,000 Falsification of online reviews, illegal non-disclosure agreements, and forcing patients to give up HIPAA rights
2024 California Adventist Health Hanford $10,000 2 Alleged unlawful disclosures of patient information to law enforcement
2024 California Blackbaud $6,750,000 5,500,000 Failure to implement appropriate safeguards to ensure data security and breach response failures – Violations of the HIPAA Security Rule, Breach Notification Rule, and state consumer protection laws
2024 California Quest Diagnostics $5,000,000 and an investment of $1.2 million in cybersecurity Unconfirmed Illegal disposal of hazardous waste, medical waste, and patients’ personal health information
2024 New York Refuah Health Center Inc. $450,000 and an investment of $1.2 million in cybersecurity 260,740 Multiple violations of the  HIPAA Security Rule, violation of the HIPAA Breach Notification Rule, and violations of New York Business Law
2023 New York New York Presbyterian Hospital $300,000 54,396 Violation of the HIPAA Privacy Rule and New York Executive Law due to the use of pixels and other website tracking tools that disclosed PHI to third parties.
2023 New York Healthplex $400,000 89,955 (62,922 New York residents) Violation of New York’s data security and consumer protection laws (data retention/logging, MFA, data security assessments)
2023 Indiana CarePointe ENT $120,000 48,742 Failure to address known vulnerabilities and a business associate agreement failure.
2023 New York U.S. Radiology Specialists $450,000 198,260 (92,540 New York residents) A failure to upgrade hardware to address a known vulnerability in a reasonable time frame.
2023 New York Personal Touch Holding Corp $350,000 753,107 (316,845 New York residents) Only had an informal information security program, insufficient access controls, no continuous monitoring system, lack of encryption, and inadequate staff training.
2023 Multistate (32 states and PR) Inmediata $1.4 million 1,565,338 Failure to implement appropriate safeguards to ensure data security and breach response failures, which violated the HIPAA Security Rule, Breach Notification Rule, and state breach notification laws
2023 Multistate (49 states and DC) Blackbaud $49.5 million 5,500,000 Violations of HIPAA and state consumer protection laws: Lack of adequate safeguards for protecting sensitive information, and breach response/ notification failures.
2023 Colorado Broomfield Skilled Nursing and Rehabilitation Center $60,000 ($25,000 suspended) 677 Violations of HIPAA data encryption requirements, state data protection laws, and deceptive trading practices.
2023 Indiana Schneck Medical Center $250,000 89,707 Violations of the HIPAA Privacy Rule, Security Rule, and Breach Notification Rule; Indiana Disclosure of Security Breach Act; Indiana Deceptive Consumer Sales Act.
2023 California Kaiser Foundation Health Plan Foundation Inc. and Kaiser Foundation Hospitals $49,000,000 7,700 Violations of the HIPAA Rules, California Hazardous Waste Control Law, Medical Waste Management Act, California Confidentiality of Medical Information Act, California Customer Records Law, and California Unfair Competition Law
2023 California Kaiser Permanente $450,000 167,095 Impermissible disclosure of PHI and negligent maintenance or disposal of  PHI in violation of the California Confidentiality of Medical Information Act (CMIA)
2023 New York Professional Business Systems Inc (dba Practicefirst Medical Management Solutions and PBS Medcode Corp $550,000 1,200,000 Data security failures: Patch management, data encryption, vulnerability scans, and penetration tests
2023 Oregon, New Jersey, Florida, Pennsylvania EyeMed Vision Care $2,500,000 2,100,000 Data security failures, including access controls
2023 New York Heidell, Pittoni, Murphy & Bach LLP $200,000 61,438 Violation of 17 HIPAA Privacy and Security Rule provisions
2023 Pennsylvania/Ohio DNA Diagnostics Center $400,000 2,100,000 Lack of safeguards, failure to update asset inventory, and failure to disable/remove assets not used for business purposes.
2022 Oregon/Utah Avalon Healthcare $200,000 14,500 Breach notification delay and information security program failures
2022 Massachusetts Aveanna Healthcare $425,000 166,000 Lack of security safeguards to combat phishing, including no multifactor authentication
2022 New York EyeMed Vision Care $600,000 2,100,000 Multiple violations of HIPAA and New York General Business Law.
2021 New Jersey Regional Cancer Care Associates (Regional Cancer Care Associates LLC, RCCA MSO LLC, and RCCA MD LLC) $425,000 105,000 Failure to ensure the confidentiality, integrity, and availability of PHI, failure to protect against reasonably anticipated threats, failure to implement security measures to reduce risks, failure to conduct an accurate risk assessment, lack of a security awareness and training program.
2021 New Jersey Command Marketing Innovations, LLC and Strategic Content Imaging LLC $130,000 (Plus $65,000 suspended) 55,715 Failure to ensure the confidentiality of PHI, lack of PHI safeguards, and a failure to review security measures following changes to procedures.
2021 New Jersey Diamond Institute for Infertility and Menopause $495,000 14,663 Multiple Privacy Rule and Security Rule failures, and violations of the Consumer Fraud Act.
2021 Multistate American Medical Collection Agency $21 million (suspended) 21,000,000 Security failures, including the failure to detect a data breach.
2020 Multistate CHSPSC LLC $5,000,000 6,100,000 Failure to implement and maintain reasonable security practices
2020 Multistate Anthem Inc $48.2 million 78,000,000 Multiple violations of HIPAA and state laws
2019 Multistate Premera Blue Cross $10,000,000 10,400,000 Multiple HIPAA violations
2019 Multistate Medical Informatics Engineering $900,000 3,500,000 Multiple HIPAA violations
2019 CA Aetna $935,000 1,991 2 mailings exposed PHI (Afib, HIV)
2018 MA McLean Hospital $75,000 1,500 Loss of backup tapes
2018 NJ EmblemHealth $100,000 81,000 Mailing error exposed SSNs
2018 NJ Best Transcription Medical $200,000 1,650 Exposure of ePHi via search engines
2018 CT Aetna $99,959 13,160 2 mailings exposed PHI (Afib, HIV data)
2018 NJ Aetna $365,211.59 13,160 2 mailings exposed PHI (Afib, HIV data)
2018 DC Aetna $175,000 13,160 2 mailings exposed PHI (Afib, HIV data)
2018 MA UMass Memorial Medical Group / UMass Memorial Medical Center $230,000 15,000 Failure to secure ePHI  and multiple breaches
2018 NY Arc of Erie County $200,000 3,751 Failure to secure ePHI
2018 NJ Virtua Medical Group $417,816 1,654 Multiple violations of HIPAA Rules
2018 NY EmblemHealth $575,000 81,122 Impermissible disclosure of ePHI
2018 NY Aetna $1,150,000 12,000 2 mailings exposed PHI (Afib, HIV data)
2017 CA Cottage Health System $2,000,000 >54,000 Failure to adequately protect medical records
2017 MA Multi-State Billing Services $100,000 2,600 Theft of an unencrypted laptop containing PHI
2017 NJ Horizon Healthcare Services Inc., $1,100,000 3,700,000 Loss of unencrypted laptop computers
2017 VT SAManage USA, Inc. $264,000 660 Spreadsheet indexed by search engines and PHI viewable
2017 NY CoPilot Provider Support Services, Inc $130,000 221,178 Delayed breach notification
2015 NY University of Rochester Medical Center $15,000 3,403 A list of patients was provided to a nurse who took it to a new employer
2015 CT Hartford Hospital/ EMC Corporation $90,000 8,883 Theft of an unencrypted laptop containing PHI
2014 MA Women & Infants Hospital of Rhode Island $150,000 12,000 Loss of backup tapes containing PHI
2014 MA Boston Children’s Hospital $40,000 2,159 Loss of a laptop containing PHI
2014 MA Beth Israel Deaconess Medical Center $100,000 3,796 Loss of a laptop containing PHI
2013 MA Goldthwait Associates $140,000 67,000 Improper disposal
2012 MN Accretive Health $2,500,000 24,000 Mishandling of PHI
2012 MA South Shore Hospital $750,000 800,000 Loss of backup tapes containing PHI
2011 VT Health Net Inc. $55,000 1,500,000 Loss of unencrypted hard drive/delayed breach notifications
2011 IN WellPoint Inc. $100,000 32,000 Failure to report a breach in a reasonable timeframe
2010 CT Health Net Inc. $250,000 1,500,000 Loss of unencrypted hard drive/delayed breach notifications

FAQs About HIPAA Violation Fines

Does the above list represent all the HIPAA violation fines issued by OCR?

As of June 2022, despite receiving more than 300,00 complaints and reports of data breaches, the HHS´ Office for Civil Rights has only issued fines or agreed settlements in 110 cases. Most of the other cases – in which a violation of HIPAA is considered to have occurred – have been resolved by technical assistance and/or corrective action plans.

Can OCR also pursue criminal charges for violations of HIPAA?

If the Office for Civil Rights reviews a case and believes there are grounds for a possible criminal conviction, the case is referred to the Department of Justice. The Department of Justice has the authority to pursue criminal charges for violations of HIPAA, and several individuals responsible for violating HIPAA have received jail sentences. These include:

Why are so many of the latest settlements for HIPAA Right of Access failures?

Since 2019, the Office for Civil Rights has been running a Right of Access enforcement initiative to address the increasing number of complaints from patients who have experienced obstacles or delays in accessing copies of PHI. This does not mean OCR is turning a blind eye to other types of HIPAA violations, and the agency continues to investigate other violations and data breaches.

Why are some HIPAA violation fines more than the annual penalty limit?

The annual penalty limit applies per violation type. Therefore, if a covered entity is found non-compliant in (for example) four areas, the non-compliant covered entity could receive four fines, each up to the maximum penalty per violation or annual penalty limit (per violation), depending on their level of culpability.

What do the four penalty/level of culpability tiers represent?

Tier 1: A violation that a Covered Entity or Business Associate was unaware of and could not have realistically avoided had a reasonable amount of care been taken to comply with HIPAA.

Tier 2: A violation that a Covered Entity or Business Associate should have been aware of but could not have avoided even with a reasonable amount of care to comply with HIPAA.

Tier 3: A violation suffered as a direct result of “willful neglect” in cases where a Covered Entity or Business Associate has made an attempt to correct the violation.

Tier 4: A violation of HIPAA attributable to willful neglect, where no attempt has been made to correct the violation by a Covered Entity or Business Associate.

The post HIPAA Violation Fines appeared first on The HIPAA Journal.

Is Saying Someone Died a HIPAA Violation?

In answer to the question is saying someone died a HIPAA violation, it depends on who is making the statement, who the statement is made to, and what other information is disclosed with the statement. Saying someone died can be a HIPAA violation, but – as this blog discusses – in most cases it is not.

Among other purposes, the HIPAA Privacy Rule protects the privacy of individually identifiable health information relating to the past, present, or future health condition of an individual. Organizations subject to the HIPAA Privacy Rule – and their workforces – must comply with this requirement with respect to a deceased individual “for a period of 50 years following the death of the individual”.

However, not all organizations are subject to the HIPAA Privacy Rule. If, for example, an employee of a private nursing home which does not qualify as a HIPAA “covered entity” revealed somebody had died, it is not a HIPAA violation because the nursing home is not required to protect the privacy of individually identifiable health information (Note: although this might not be a violation of HIPAA, disclosing private information of this nature may violate state privacy laws in some circumstances).

Even when an organization is subject to the HIPAA Privacy Rule, it is not automatically the case that saying someone died is a HIPAA violation. “Covered entities” are permitted to disclose individually identifiable health information to specific people, subject to the disclosure being limited to the minimum necessary to achieve the purpose of the disclosure, and subject to any prior expressed wish of the deceased relating to what information can be disclosed. Healthcare providers should receive HIPAA training on permitted disclosures of this nature.

Who Can Be Told Someone Has Died Under HIPAA?

The HIPAA Privacy Rule stipulates who can be told when someone has died in sections §164.510(b) and §164.512(g). The first section allows covered entities to disclose information about deceased individuals to family members, other relatives, close personal friends, or any other individual identified by the deceased individual while they were alive. All disclosures to people in this group are subject to the verification requirements of §164.514(h).

Persons or entities that were involved in the deceased person´s care or payment for health care can also be told the patient has died under §164.510(b), while §164.512(g) permits covered entities to disclose individually identifiable health information to a coroner or medical examiner to identify the deceased person, determine the cause of death, or other duty as authorized by law. Under this section, covered entities can also tell funeral directors somebody has died.

In all permitted circumstances, the information disclosed must be the minimum necessary to achieve the purpose of the disclosure, and must respect any wishes known by the covered entity prior to the patient’s death. If a patient died (say) due to injuries sustained in a road accident, but also suffered from a lung condition, covered entities are not permitted to disclose the lung condition or any other related treatment or payment for the treatment.

When is Saying Someone Died a HIPAA Violation?

There are not many circumstances when saying someone died is a HIPAA violation and usually violations of this nature only occur when a member of a covered entity’s workforce:

  • Discloses information to somebody not permitted by the HIPAA Privacy Rule,
  • Discloses more than the minimum necessary information about the deceased, or
  • Discloses information it is known the deceased did not want disclosed.

However, it is important to note the HIPAA Privacy Rule generally applies to a deceased person’s health information in the same way as a living person’s health information. In the same way as an individual’s “personal representative” can authorize disclosures of health information not permitted by the HIPAA Privacy Rule on the individual’s behalf when they are alive, a personal representative can do the same when the individual is deceased.

In most states, a deceased individual’s “personal representative” is the next of kin. If the next of kin authorizes a disclosure to somebody not permitted by the HIPAA Privacy Rule, a disclosure of more than the minimum necessary information, or a disclosure of information the deceased did not want disclosed, these events are no longer HIPAA compliance violations. If you are still uncertain about when is saying someone died a HIPAA violation, you should seek professional compliance advice.

The post Is Saying Someone Died a HIPAA Violation? appeared first on The HIPAA Journal.