Drug & Alcohol Treatment Services Ransomware Settlement

HIPAA compliance documentation list

HIPAA Compliance Lessons for Healthcare Providers

Healthcare organizations continue to face an unprecedented wave of ransomware attacks, and the financial consequences extend well beyond regulatory penalties.

The latest example involves Drug and Alcohol Treatment Services, Inc. (DATS), an addiction treatment provider based in Scranton, Pennsylvania. The organization has agreed to settle multiple class action lawsuits arising from an October 2024 ransomware attack that compromised sensitive patient information.

While every healthcare breach has unique circumstances, this case reinforces a lesson every covered entity and business associate should understand:

HIPAA compliance is no longer just about policies and employee training—it must include a comprehensive cybersecurity program.

What Happened?

According to public reports, cybercriminals gained unauthorized access to DATS’ network between October 5 and October 6, 2024. Following its investigation, the organization determined that both protected health information (PHI) and personally identifiable information (PII) had been compromised. The breach affected approximately 22,215 individuals.

The Cost of a Breach is just the beginning

The ransomware attack resulted in far more than the technical challenges of restoring systems and investigating the incident.

According to public reports, multiple lawsuits were consolidated into a single class action, culminating in a proposed $549,000 settlement. As part of the settlement, DATS also agreed to maintain and strengthen its information security program for a period of five years, reinforcing the long-term operational and financial impact that a data breach can have on a healthcare organization.

Often, the long-term business impact exceeds the initial ransomware event.

Why OCR Looks Beyond the Attack

One of the biggest misconceptions in healthcare is that organizations are fined simply because they were hacked.

That is not how HIPAA enforcement typically works.

The HHS Office for Civil Rights (OCR) generally evaluates whether the organization had implemented the reasonable and appropriate safeguards required by the HIPAA Security Rule before the attack occurred.

OCR commonly reviews whether an organization had:

  • Conducted an enterprise-wide security risk analysis
  • Implemented a documented risk management plan
  • Maintained current HIPAA policies and procedures
  • Provided workforce HIPAA training
  • Managed vendor and Business Associate Agreements
  • Maintained incident response procedures
  • Reviewed audit logs and system activity
  • Implemented strong access controls
  • Used multi-factor authentication where appropriate
  • Protected systems with encryption and backups

Organizations that cannot demonstrate these safeguards often face much greater regulatory scrutiny following a breach.

Behavioral Health Organizations Face Higher Privacy Risks

For an addiction treatment provider, the exposure of this type of information is especially concerning because it includes records related to behavioral health and substance use disorder (SUD) treatment. In addition to HIPAA, many SUD treatment records are subject to the heightened confidentiality requirements of 42 CFR Part 2, which imposes stricter protections on the use and disclosure of patient information. A breach involving these records can have significant legal, financial, and reputational consequences, making robust cybersecurity and privacy safeguards essential.

Organizations providing behavioral health, psychiatric, addiction treatment, and substance use services often maintain some of the most sensitive healthcare records.

A ransomware attack affecting these organizations may expose information that patients consider deeply personal, increasing both legal exposure and reputational harm.

Because of the sensitive nature of behavioral health records, providers should regularly review both their HIPAA compliance program and applicable federal and state privacy requirements.

Lessons Every Healthcare Organization Should Learn

Every ransomware incident should prompt healthcare organizations to ask:

  • When was our last Security Risk Analysis?
  • Have we documented how risks are being addressed?
  • Are employees receiving annual HIPAA and cybersecurity training?
  • Are our Business Associate Agreements current?
  • Do we test our incident response and contingency plans?
  • Could we demonstrate compliance during an OCR investigation?

If the answer to any of these questions is “I’m not sure,” now is the time to act, not after a cyberattack.

Summary

The DATS settlement is another reminder that ransomware is no longer a question of if, but when.

Healthcare organizations that invest in both cybersecurity and documented HIPAA compliance place themselves in a much stronger position to protect patients, respond effectively to incidents, and demonstrate compliance if regulators come calling. Thus, protecting them from potential class action lawsuits.

As OCR frequently reminds covered entities, documentation matters.

If it’s not documented, it may be difficult to prove it was ever done.

How the HIPAA Keeper™ Helps

The HIPAA Keeper™ was designed to help healthcare organizations build and maintain a documented compliance program that supports the requirements of the HIPAA Privacy Rule and Security Rule.

The platform helps organizations:

  • Complete annual Security Risk Analyses
  • Develop Risk Management Plans
  • Maintain required HIPAA documentation
  • Train employees
  • Track Business Associate Agreements
  • Document compliance activities
  • Prepare for OCR audits
  • Stay organized throughout the year

Cybersecurity tools help prevent attacks. HIPAA compliance helps demonstrate that your organization took reasonable steps to protect patient information before an attack occurred.

Both are essential.

Don’t leave patient data exposed.

At Aris Medical Solutions, our online HIPAA Keeper™ system helps healthcare providers and business associates maintain full compliance.


Schedule your HIPAA Risk Analysis and Access Control Review with Aris Medical Solutions today.

About Suze Shaffer

Suze Shaffer is the owner and president of Aris Medical Solutions. She specializes in HIPAA compliance, risk management, and cyber security. She believes that by educating her clients in understanding why and what needs to be done to protect their practice they have a better outcome.

Suze has been instrumental in helping clients nationwide with risk management, implementing privacy and security rule policies and procedures, and ultimately protecting patient data. She includes state and federal regulatory requirements to ensure clients are protected in all areas.

She has spoken at numerous conferences and functions. She continues to educate organizations how to minimize the risks of data breaches. HIPAA compliance is not an option, it is mandatory for every organization that comes in contact with protected health information to have reasonable and appropriate security measures in place. Unfortunately, most organizations don’t realize they are not compliant until they suffer a data breach or they are faced with an audit or investigation.

Did you know that the Office for Civil Rights (OCR) is the agency that investigates data breaches? Have you seen the heavy fines that have been imposed for non-compliance?

All 50 states now have their own set of privacy laws and the State's Attorney General may also investigate privacy violations!

Class Action Lawsuits against Medical Practices

May 22, 2026

OSF HealthCare Pays $552,250 to Settle HIPAA Investigation

July 30, 2026
©2026 Aris Medical Solutions – HIPAA Keeper | HIPAA Compliance Consultants | All Rights Reserved | Terms and Conditions | Privacy Policy
The content and images on this website is owned by Aris Medical Solutions and their owners. Do not copy any content or images without our consent.
Powered by Bandwise LLC