Drug & Alcohol Treatment Services Ransomware Settlement

HIPAA Compliance Lessons for Healthcare Providers

Healthcare organizations continue to face an unprecedented wave of ransomware attacks, and the financial consequences extend well beyond regulatory penalties.

The latest example involves Drug and Alcohol Treatment Services, Inc. (DATS), an addiction treatment provider based in Scranton, Pennsylvania. The organization has agreed to settle multiple class action lawsuits arising from an October 2024 ransomware attack that compromised sensitive patient information.

While every healthcare breach has unique circumstances, this case reinforces a lesson every covered entity and business associate should understand:

HIPAA compliance is no longer just about policies and employee training—it must include a comprehensive cybersecurity program.

What Happened?

According to public reports, cybercriminals gained unauthorized access to DATS’ network between October 5 and October 6, 2024. Following its investigation, the organization determined that both protected health information (PHI) and personally identifiable information (PII) had been compromised. The breach affected approximately 22,215 individuals.

The Cost of a Breach is just the beginning

The ransomware attack resulted in far more than the technical challenges of restoring systems and investigating the incident.

According to public reports, multiple lawsuits were consolidated into a single class action, culminating in a proposed $549,000 settlement. As part of the settlement, DATS also agreed to maintain and strengthen its information security program for a period of five years, reinforcing the long-term operational and financial impact that a data breach can have on a healthcare organization.

Often, the long-term business impact exceeds the initial ransomware event.

Why OCR Looks Beyond the Attack

One of the biggest misconceptions in healthcare is that organizations are fined simply because they were hacked.

That is not how HIPAA enforcement typically works.

The HHS Office for Civil Rights (OCR) generally evaluates whether the organization had implemented the reasonable and appropriate safeguards required by the HIPAA Security Rule before the attack occurred.

OCR commonly reviews whether an organization had:

  • Conducted an enterprise-wide security risk analysis
  • Implemented a documented risk management plan
  • Maintained current HIPAA policies and procedures
  • Provided workforce HIPAA training
  • Managed vendor and Business Associate Agreements
  • Maintained incident response procedures
  • Reviewed audit logs and system activity
  • Implemented strong access controls
  • Used multi-factor authentication where appropriate
  • Protected systems with encryption and backups

Organizations that cannot demonstrate these safeguards often face much greater regulatory scrutiny following a breach.

Behavioral Health Organizations Face Higher Privacy Risks

For an addiction treatment provider, the exposure of this type of information is especially concerning because it includes records related to behavioral health and substance use disorder (SUD) treatment. In addition to HIPAA, many SUD treatment records are subject to the heightened confidentiality requirements of 42 CFR Part 2, which imposes stricter protections on the use and disclosure of patient information. A breach involving these records can have significant legal, financial, and reputational consequences, making robust cybersecurity and privacy safeguards essential.

Organizations providing behavioral health, psychiatric, addiction treatment, and substance use services often maintain some of the most sensitive healthcare records.

A ransomware attack affecting these organizations may expose information that patients consider deeply personal, increasing both legal exposure and reputational harm.

Because of the sensitive nature of behavioral health records, providers should regularly review both their HIPAA compliance program and applicable federal and state privacy requirements.

Lessons Every Healthcare Organization Should Learn

Every ransomware incident should prompt healthcare organizations to ask:

  • When was our last Security Risk Analysis?
  • Have we documented how risks are being addressed?
  • Are employees receiving annual HIPAA and cybersecurity training?
  • Are our Business Associate Agreements current?
  • Do we test our incident response and contingency plans?
  • Could we demonstrate compliance during an OCR investigation?

If the answer to any of these questions is “I’m not sure,” now is the time to act, not after a cyberattack.

Summary

The DATS settlement is another reminder that ransomware is no longer a question of if, but when.

Healthcare organizations that invest in both cybersecurity and documented HIPAA compliance place themselves in a much stronger position to protect patients, respond effectively to incidents, and demonstrate compliance if regulators come calling. Thus, protecting them from potential class action lawsuits.

As OCR frequently reminds covered entities, documentation matters.

If it’s not documented, it may be difficult to prove it was ever done.

How the HIPAA Keeper™ Helps

The HIPAA Keeper™ was designed to help healthcare organizations build and maintain a documented compliance program that supports the requirements of the HIPAA Privacy Rule and Security Rule.

The platform helps organizations:

  • Complete annual Security Risk Analyses
  • Develop Risk Management Plans
  • Maintain required HIPAA documentation
  • Train employees
  • Track Business Associate Agreements
  • Document compliance activities
  • Prepare for OCR audits
  • Stay organized throughout the year

Cybersecurity tools help prevent attacks. HIPAA compliance helps demonstrate that your organization took reasonable steps to protect patient information before an attack occurred.

Both are essential.

Don’t leave patient data exposed.

At Aris Medical Solutions, our online HIPAA Keeper™ system helps healthcare providers and business associates maintain full compliance.


Schedule your HIPAA Risk Analysis and Access Control Review with Aris Medical Solutions today.

Vision Upright MRI fined $25K

OCR Settlement with Vision Upright MRI: The Risk of Unsecured PACS Servers

The U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR), has reached a settlement with Vision Upright MRI LLC (VUM) after finding that the medical imaging provider exposed patient information online through an unsecured Picture Archiving and Communication System (PACS) server.

This case serves as another reminder that failing to secure medical imaging systems or perform a HIPAA compliant risk analysis can result in costly investigations, corrective action plans, and long-term monitoring by federal regulators.

How the Breach Happened

VUM operated a PACS server used to store and share diagnostic images such as MRIs, CT scans, and X-rays. OCR received reports that this server allowed public access to patients’ protected health information (PHI), including images, metadata, and identifying details.

On December 1, 2020, OCR notified VUM of a formal investigation into potential violations of the HIPAA Privacy, Security, and Breach Notification Rules. The inquiry focused on whether VUM had conducted proper risk assessments, secured its systems, and met notification deadlines required after discovering a breach.

OCR’s Findings

OCR determined that Vision Upright MRI:

  • Failed to conduct a HIPAA risk analysis — VUM had never performed an accurate and thorough assessment of potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information (ePHI), violating 45 C.F.R. § 164.308(a)(1)(ii)(A).
  • Failed to issue timely breach notifications — The organization did not notify affected individuals within 60 days of discovering the exposure, violating 45 C.F.R. § 164.404(a).

These lapses demonstrated that VUM lacked essential safeguards and incident-response procedures required under the HIPAA Security Rule.

Settlement Terms and Corrective Actions

As part of the settlement, VUM agreed to pay the Resolution Amount and implement a comprehensive Corrective Action Plan (CAP) overseen by OCR. The CAP requires the practice to:

  • Conduct a full organization-wide risk analysis, including vulnerability scans and penetration testing.
  • Develop a risk management plan to mitigate identified security gaps.
  • Update and distribute HIPAA Privacy, Security, and Breach Notification policies to all workforce members.
  • Provide annual HIPAA training for all staff with access to ePHI.
  • Investigate and report workforce noncompliance events on a quarterly basis.
  • Submit annual compliance reports to OCR and retain related documentation for six years.

This agreement is binding on VUM and its successors, emphasizing OCR’s expectation that covered entities maintain compliance over time—not just during the settlement period.

Lessons for Healthcare Providers and Business Associates

The VUM case highlights several key takeaways for any healthcare organization that handles PHI:

  1. Unsecured PACS servers are a known risk.
    Imaging systems frequently store and transmit PHI yet are often overlooked in IT risk analyses. Ensure every device and data repository is included in your risk inventory and tested for vulnerabilities.
  2. Risk analysis is not optional.
    HIPAA requires ongoing, accurate, and thorough assessments. This is not a one-time checkbox. Document each risk analysis, update it annually, and link findings directly to your risk-management plan.
  3. Breach notifications must be timely.
    Delays beyond 60 days can lead to enforcement actions. Have an incident-response plan ready so you can notify affected individuals and OCR within the required window.
  4. Policies and training are the front line of compliance.
    Workforce awareness is critical. Staff who access PHI must understand how to handle data securely and report potential issues immediately.
  5. OCR oversight can last years.
    Corrective Action Plans often require multi-year reporting and documentation retention. Establishing compliance habits early reduces disruption and risk later.

Summary

This settlement underscores a critical lesson: A thorough, documented risk analysis, an active risk management plan, and appropriate policies and procedures are essential in preventing data breaches. This process is long and grueling and could have easily been avoided.

HIPAA Keeper™ by Aris Medical Solutions simplifies compliance with:

  • Built-in risk analysis and management plans
  • Customizable policies and procedures
  • Workforce training tracking and certificates
  • Secure Breach Notification and Incident Response forms

Stay ahead of OCR investigations—protect your patients, your reputation, and your practice.

Don’t leave patient data exposed.

Schedule your HIPAA Risk Analysis with Aris Medical Solutions today.

©2026 Aris Medical Solutions – HIPAA Keeper | HIPAA Compliance Consultants | All Rights Reserved | Terms and Conditions | Privacy Policy
The content and images on this website is owned by Aris Medical Solutions and their owners. Do not copy any content or images without our consent.
Powered by Bandwise LLC