Drug & Alcohol Treatment Services Ransomware Settlement

HIPAA Compliance Lessons for Healthcare Providers

Healthcare organizations continue to face an unprecedented wave of ransomware attacks, and the financial consequences extend well beyond regulatory penalties.

The latest example involves Drug and Alcohol Treatment Services, Inc. (DATS), an addiction treatment provider based in Scranton, Pennsylvania. The organization has agreed to settle multiple class action lawsuits arising from an October 2024 ransomware attack that compromised sensitive patient information.

While every healthcare breach has unique circumstances, this case reinforces a lesson every covered entity and business associate should understand:

HIPAA compliance is no longer just about policies and employee training—it must include a comprehensive cybersecurity program.

What Happened?

According to public reports, cybercriminals gained unauthorized access to DATS’ network between October 5 and October 6, 2024. Following its investigation, the organization determined that both protected health information (PHI) and personally identifiable information (PII) had been compromised. The breach affected approximately 22,215 individuals.

The Cost of a Breach is just the beginning

The ransomware attack resulted in far more than the technical challenges of restoring systems and investigating the incident.

According to public reports, multiple lawsuits were consolidated into a single class action, culminating in a proposed $549,000 settlement. As part of the settlement, DATS also agreed to maintain and strengthen its information security program for a period of five years, reinforcing the long-term operational and financial impact that a data breach can have on a healthcare organization.

Often, the long-term business impact exceeds the initial ransomware event.

Why OCR Looks Beyond the Attack

One of the biggest misconceptions in healthcare is that organizations are fined simply because they were hacked.

That is not how HIPAA enforcement typically works.

The HHS Office for Civil Rights (OCR) generally evaluates whether the organization had implemented the reasonable and appropriate safeguards required by the HIPAA Security Rule before the attack occurred.

OCR commonly reviews whether an organization had:

  • Conducted an enterprise-wide security risk analysis
  • Implemented a documented risk management plan
  • Maintained current HIPAA policies and procedures
  • Provided workforce HIPAA training
  • Managed vendor and Business Associate Agreements
  • Maintained incident response procedures
  • Reviewed audit logs and system activity
  • Implemented strong access controls
  • Used multi-factor authentication where appropriate
  • Protected systems with encryption and backups

Organizations that cannot demonstrate these safeguards often face much greater regulatory scrutiny following a breach.

Behavioral Health Organizations Face Higher Privacy Risks

For an addiction treatment provider, the exposure of this type of information is especially concerning because it includes records related to behavioral health and substance use disorder (SUD) treatment. In addition to HIPAA, many SUD treatment records are subject to the heightened confidentiality requirements of 42 CFR Part 2, which imposes stricter protections on the use and disclosure of patient information. A breach involving these records can have significant legal, financial, and reputational consequences, making robust cybersecurity and privacy safeguards essential.

Organizations providing behavioral health, psychiatric, addiction treatment, and substance use services often maintain some of the most sensitive healthcare records.

A ransomware attack affecting these organizations may expose information that patients consider deeply personal, increasing both legal exposure and reputational harm.

Because of the sensitive nature of behavioral health records, providers should regularly review both their HIPAA compliance program and applicable federal and state privacy requirements.

Lessons Every Healthcare Organization Should Learn

Every ransomware incident should prompt healthcare organizations to ask:

  • When was our last Security Risk Analysis?
  • Have we documented how risks are being addressed?
  • Are employees receiving annual HIPAA and cybersecurity training?
  • Are our Business Associate Agreements current?
  • Do we test our incident response and contingency plans?
  • Could we demonstrate compliance during an OCR investigation?

If the answer to any of these questions is “I’m not sure,” now is the time to act, not after a cyberattack.

Summary

The DATS settlement is another reminder that ransomware is no longer a question of if, but when.

Healthcare organizations that invest in both cybersecurity and documented HIPAA compliance place themselves in a much stronger position to protect patients, respond effectively to incidents, and demonstrate compliance if regulators come calling. Thus, protecting them from potential class action lawsuits.

As OCR frequently reminds covered entities, documentation matters.

If it’s not documented, it may be difficult to prove it was ever done.

How the HIPAA Keeper™ Helps

The HIPAA Keeper™ was designed to help healthcare organizations build and maintain a documented compliance program that supports the requirements of the HIPAA Privacy Rule and Security Rule.

The platform helps organizations:

  • Complete annual Security Risk Analyses
  • Develop Risk Management Plans
  • Maintain required HIPAA documentation
  • Train employees
  • Track Business Associate Agreements
  • Document compliance activities
  • Prepare for OCR audits
  • Stay organized throughout the year

Cybersecurity tools help prevent attacks. HIPAA compliance helps demonstrate that your organization took reasonable steps to protect patient information before an attack occurred.

Both are essential.

Don’t leave patient data exposed.

At Aris Medical Solutions, our online HIPAA Keeper™ system helps healthcare providers and business associates maintain full compliance.


Schedule your HIPAA Risk Analysis and Access Control Review with Aris Medical Solutions today.

Top of the World Ranch Treatment Center Settles with OCR

The U.S. Department of Health and Human Services Office for Civil Rights announced a settlement with Top of the World Ranch Treatment Center (TWRTC) in the amount of $103,000.

The HIPAA Security Rule requires administrative, physical, and technical safeguards to protect electronic PHI. The Risk Analysis standard requires organizations to assess risks and vulnerabilities to ePHI. Covered entities and business associates must comply with the Risk Analysis requirement.

Organizations must identify where ePHI is stored and transmitted to protect it properly. This is another example of why system wide risk analyses are so important.


OCR opened its investigation after TWRTC reported a breach in March 2023.
A phishing attack allowed an unauthorized party to access ePHI through an employee’s email account. The attack exposed the ePHI of 1,980 patients.

OCR determined that TWRTC failed to conduct an accurate and thorough risk analysis. This failure violated the HIPAA Security Rule.

TWRTC also agreed to implement a corrective action plan monitored for two years.

Under the corrective action plan, TWRTC must:

• Conduct and complete an accurate and thorough risk analysis to identify risks and vulnerabilities to ePHI.

• Develop and implement a risk management plan to address identified security risks and vulnerabilities.

• Create, maintain, and update written policies and procedures to comply with HIPAA Privacy, Security, and Breach Notification Rules.

• Employees serve as the first line of defense against cyber threats. Provide annual HIPAA training to workforce members who access ePHI.

Recommendations:

• Identify where ePHI is stored and how it enters, moves through, and exits your systems.

• Conduct regular risk analyses and update risk management measures to address identified vulnerabilities.

• Implement audit controls to record and examine system activity.

• Review system activity regularly to detect suspicious behavior.

• Use authentication mechanisms to verify users before granting access to ePHI.

• Encrypt ePHI in transit and at rest when appropriate to prevent unauthorized access.

• Incorporate lessons from security incidents into your security management process.

At Aris Medical Solutions, our online HIPAA Keeper™ is an all in one secure, cloud-based system that helps healthcare providers and business associates simplify compliance by maintaining their risk analyses, up-to-date policies, procedures, HIPAA training and documentation to meet every aspect of the HIPAA Privacy and Security Rules.

Protect your organization before an attack happens.

Schedule your HIPAA compliance review today and protect your organization from the next enforcement headline.

©2026 Aris Medical Solutions – HIPAA Keeper | HIPAA Compliance Consultants | All Rights Reserved | Terms and Conditions | Privacy Policy
The content and images on this website is owned by Aris Medical Solutions and their owners. Do not copy any content or images without our consent.
Powered by Bandwise LLC