HIPAA Violations & Fines

HIPAA Violations & Fines

Keeping you informed and prepared

BST & Co. CPAs, LLP fined $175K for Ransomware Breach

BST & Co. CPAs, LLP fined $175K for Ransomware Breach

OCR Issues 15th Ransomware Enforcement Action and 10th Enforcement Action in Risk Analysis Initiative The U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR) announced a settlement with BST & Co. CPAs, LLP (“BST”), a New...
Read More
Syracuse ASC fined $250K for Ransomware

Syracuse ASC fined $250K for Ransomware

A Costly Reminder of HIPAA’s Ransomware Readiness Requirements. The U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR), announced a settlement with Syracuse ASC, LLC, doing business as Specialty Surgery Center of Central New York, for...
Read More
Deer Oaks – The Behavioral Health Solution fined $225K

Deer Oaks – The Behavioral Health Solution fined $225K

The U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR) has the authority to investigate complaints and conduct compliance reviews involving potential violations of the HIPAA Privacy, Security, and Breach Notification Rules by covered entities and...
Read More
Comstar, a Business Associate fined $75K for Ransomware Attack

Comstar, a Business Associate fined $75K for Ransomware Attack

The Office for Civil Rights (OCR) has the authority to conduct compliance reviews and investigations of complaints alleging violations of the Privacy, Security, and Breach Notification Rules (the "HIPAA Rules") by covered entities and business associates. Comstar, LLC ("Comstar") meets...
Read More
Baycare Health System fined $800K for Impermissible Access Exploited by a Malicious Insider

Baycare Health System fined $800K for Impermissible Access Exploited by a Malicious Insider

The U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR), announced a settlement with BayCare Health System, a Florida-based healthcare provider, for potential violations of the HIPAA Security Rule. The case stemmed from a complaint alleging...
Read More
Vision Upright MRI fined $25K

Vision Upright MRI fined $25K

OCR Settlement with Vision Upright MRI: The Risk of Unsecured PACS Servers The U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR), has reached a settlement with Vision Upright MRI LLC (VUM) after finding that the...
Read More
Change Healthcare Cyberattack

Change Healthcare Cyberattack

The U.S. Department of Health and Human Services’ Office for Civil Rights (OCR) issued a “Dear Colleague” letter about the Change Healthcare cyberattack. OCR also opened an official investigation. The attack affects Change Healthcare, a unit of UnitedHealthcare Group (UHG),...
Read More
Montefiore Medical Center fined $4.75M for Malicious Insider

Montefiore Medical Center fined $4.75M for Malicious Insider

The U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR) announced a $4.75 million settlement with Montefiore Medical Center, a New York City hospital system. The settlement resolves multiple potential HIPAA Security Rule violations. OCR enforces...
Read More
Patient Right of Access delays cost Optum Medical Care $160K

Patient Right of Access delays cost Optum Medical Care $160K

Optum Medical Care (formerly known as Riverside Medical Group and Riverside Pediatric Group) is a large multi-specialty physician group serving patients throughout New Jersey and Southern Connecticut. Optum has agreed to pay $160,000 and implement a Corrective Action Plan (CAP)...
Read More
Green Ridge Behavioral Health is Second Ransomware Settlement

Green Ridge Behavioral Health is Second Ransomware Settlement

The U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR) announced a settlement with Green Ridge Behavioral Health, LLC, a Maryland psychiatric practice. The case involved a ransomware attack that compromised the protected health information of...
Read More
©2025 Aris Medical Solutions – HIPAA Keeper | HIPAA Compliance Consultants | All Rights Reserved | Terms and Conditions | Privacy Policy
The content and images on this website is owned by Aris Medical Solutions and their owners. Do not copy any content or images without our consent.
Powered by Bandwise LLC