Skip to content
  • About Us
    • Who We Serve
  • Solutions
    • HIPAA for Covered Entities
    • OSHA for Healthcare
    • HIPAA for Business Associates
    • SRA for Covered Entities
    • Abyde Incident Response Program
    • Abyde Reseller Program
  • Resources
  • News
  • Events
  • Partners
  • Contact Us
  • Login
    • HIPAA for Covered Entities
    • OSHA for Healthcare
    • HIPAA for Business Associates
    • SRA for Covered Entities
SIGN UP
BOOK A DEMO

2021 HIPAA in Review

December 28, 2021

Break out your pen and paper because if you haven’t already started your list of new year’s resolutions, the past 12 months have given us plenty of ‘New Year, new me’ examples to take note of. From ratified legislation and appointed government officials to trending cyberthreat tactics (and binge-worthy Netflix series), there have been plenty of ways that 2021 has said, “out with the old, and in with the new”. But while the world around us continues to evolve, the importance of protecting your patients is something that has not and will never falter. So as we wrap up yet another eventful year – let’s take a look at what’s changed, what’s stayed the same and what we can expect to see from HIPAA as we take on 2022. 

Proposed HIPAA Privacy Rule Modifications

2021’s transformations began even before the new year countdown started with the announcement of proposed HIPAA Privacy Rule modifications made back in December 2020. The government’s proposed modifications help bring the HIPAA Privacy Rule up to current technology standards and address things like removing the barriers to value-based health care, reducing “unnecessary regulatory burdens” and improving the privacy of protected health information (PHI). These highlights only brush the surface of what the 357-page document aims to amend but until the ruling is officially finalized, it’s important for your practice to ensure your HIPAA compliance program is up to date and easy to manageas we should anticipate the new requirements coming into effect in the new year.

HIPAA Safe Harbor Law

2021 checked off another one of its resolution list items back in early January by officially signing the HIPAA Safe Harbor Bill into law. The amendment of the HITECH Act takes into account whether healthcare organizations have “recognized cybersecurity practices” in place and allows for some leniency in fines and other enforcement actions in the case of a data breach. While there’s a bit of fine print to follow, the biggest thing for your practice to know is that as long as you have a Security Risk Analysis (SRA), technical safeguards, and other HIPAA Security Rule basics down – you can not only reduce the penalties associated with a data breach but lessen your chances of falling victim in the first place.

21st Century Cures Act

Following the Safe Harbor Law’s lead, the 21st Century Cures Act came into effect just a few months later in April of 2021. The new legislation directed by the Office of the National Coordinator for Healthcare Technology (ONC) is centered around the ongoing balancing act that healthcare providers and app developers face in giving patients easy access to their ePHI while still maintaining data privacy and security. With patients at the focus, the Cures Act requirements enable things like transparency into the cost and outcomes of patient care, easier access to health data through apps that meet modern patient needs and the prevention of information blocking. Now, this law also requires a bit of further reading to see just how it impacts your practice but having a complete HIPAA program lays the foundation for meeting these additional requirements and ultimately protecting patient data. 

Proposed Budget & New Appointed OCR Director 

If all the new legislation wasn’t enough of a tell-tale sign that 2021 was the year of protecting patient rights along with healthcare and technology – the proposed 2022 HHS budget that increases its funding for those areas specifically sure is. In early June, the Biden Administration released their proposed budget calling for additional spending to better safeguard the healthcare industry from evolving cyber threats and support government efforts in compliance enforcement. This additional spending comes in the form of over $200 million for several different cybersecurity measures and $67 million in funding for the HHS and their HIPAA enforcement efforts. Much of this proposed budget includes an increase in hiring for these specific government agencies with the hope to add 39 staff members to the Office for Civil Rights (OCR) specifically. But the initiatives don’t just stop at the dollar signs – this past September the HHS officially appointed Lisa J. Pino as the new Director of the OCR, marking another step in the right direction of continuing their mission.

HIPAA Waivers Extended 

In the midst of all the change, there have been some things that have stayed the same – one of them being the extension of the HIPAA Waivers and Enforcement Discretions. At the onset of COVID-19, the government issued a National Public Health Emergency. With it came several waivers and flexibilities that work in mitigating the risks to the health of the general public while assisting healthcare providers with the necessary accommodations to continue caring for their patients. So after several extensions to the waiver’s expiration date, we are starting off our second new year with the Public Health Emergency status with the hopes that the current end date of January 16, 2022 sticks. But even with the current flexibilities still in place, it’s important to adhere to HIPAA requirements for telehealth and PHI disclosure to avoid any violations once the enforcement discretion is lifted. 

Patient Right of Access Enforcement 

Now a seasoned veteran to the regulatory priority list, Patient Right of Access violations has had yet another impactful year in HIPAA enforcement. 2021’s Right of Access settlements has brought the total violation number to 25 and dollars collected to $1,505,650 since the government announced their initiative back in 2019. And just a few weeks ago, the OCR announced 5 Right of Access settlements in one day alone. So as the government’s focus on timely medical record access continues to reign, your practice should be adding HIPAA right of access standards to the top of your 2022 to-do list too. 

Data Breaches

Last but certainly not least comes another trend that has shown little to no signs of stopping –  data breaches. Between ransomware threats, phishing schemes, accidental disclosures and business associate incidents, 2021 has put up record numbers. And just in the past year alone, a total of 550 covered entities had experienced a data breach putting the PHI of over 40 million individuals at risk. So while maintaining strong cybersecurity within your organization is easier said than done, knowing how to identify a cyber threat and having the necessary technical safeguards to mitigate your risks are essential to protecting your practice and your patients from a data breach in 2022. 

Now we know we just gave you a lot to unpack but each and every one of 2021’s resolutions play an important role in dictating your organization’s new year solutions. No matter what, healthcare, technology and patient needs are always evolving, and ensuring your practice’s success means having the necessary programs in place to do just that. But while we don’t expect HIPAA to be at the top of everyone’s list of resolutions – with Abyde, compliance can be the easiest one to check off. So make 2022 the year of peace of mind and protection with a software solution so revolutionary, you’ll have to see it for yourself. 

 

RECENT POSTS

  • OSF Healthcare HIPAA Settlement
    What OSF Healthcare's Ransomware Fine Teaches Every Practice About SRAs
  • Spencer Gifts HIPAA Fine
    Spencer Gifts HIPAA Settlement: Ransomware, Risk Analysis, and What Comes Next
  • OCR Ransomware Settlements
    OCR Ransomware Settlements: 4 Massive HIPAA Fines from April 2026 & How to Avoid Them
PrevPreviousVirginia Optometric Association and Abyde partner to deliver HIPAA compliance to independent eye care professionals
NextAbyde Partners With VisionWeb to Provide Complete HIPAA Compliance Solutions for Eye Care ProfessionalsNext

Related posts

OSF Healthcare HIPAA Settlement
Abyde News, Fines, HIPAA

What OSF Healthcare’s Ransomware Fine Teaches Every Practice About SRAs

August 5, 2026 Penelope Schweitzer No comments yet

August 5, 2026 The latest HIPAA fine is another clear reminder that ransomware attacks are, unfortunately, here to stay in the healthcare industry. A settlement involving the OSF Healthcare System was recently announced by the Office for Civil Rights (OCR). As an enterprise healthcare provider in the midwest, the organization serves 174 locations, including 16 hospitals – a prime target for a ransomware attack.    So, what happened?  In April 2021, OSF discovered that they joined the unlucky club of ransomware victims when a malicious actor deployed Nephilim, a ransomware strain made to target larger organizations. Once the ransomware infected OSF systems, the hacker demanded payment or patient Protected Health Information (PHI) would be leaked online. In this attack, sensitive information like financial account information, driver’s license numbers, medical record numbers, and more, were all exposed. Over 53,000 patient records were exposed in this attack.  When ransomware attacks in healthcare have soared 278% in recent years, it’s more of a when then an if your organization doesn’t have the right safeguards in place.  While the breach was discovered in April, OSF healthcare reported the breach to the OCR in October. The OCR took it from there, digging into what precautions (or lack thereof) let this happen.  What did the OCR discover? If you’ve read any of our other fine breakdowns, you already know where this is going: another missing Security Risk Analysis (SRA).  The SRA is a required document every HIPAA-regulated entity (ie: every practice and their Business Associates that handle patient information) needs to complete. The SRA is a thorough review of the physical, technical, and administrative safeguards in place to prevent PHI ending up in the wrong hands. While the OCR didn’t specify exactly how the ransomware got into OSF’s system, a technical safeguard vulnerability was very likely the entry point. A proactive SRA could have flagged that gap before it turned into a major breach. In addition to missing this required documentation, OSF also took too long to report the breach to the OCR and notify affected patients. This is a direct violation of the Breach Notification Rule, which requires organizations to notify patients within 60 days of a discovered breach. Moreover, since the breach impacted more than 500 patients, OSF was also required to report this breach to the OCR within 2 months as well. Time is of the essence in every component of a breach, from securing systems to ensuring affected parties are aware to protect themselves and an over five month delay was unacceptable in the eyes of the OCR.    What was the result?  OSF’s settlement tops the list as the largest fine of the year, coming in at $552,250, plus government monitoring for the next two years.  It’s very important to note that this breach occurred in 2021, meaning that over five years were spent from the initial breach, to investigations, to the public press releases. Also, the average cost of a healthcare breach is over 7 million dollars –  from implementing secure systems, notifying patients, legal fees, and more. The Takeaway While the settlement payment and Corrective Action Plan (CAP) are just the cherries on top, this experience was a tremendous cost of time, money, and resources, highlighting the importance of making sure everything is secure before a situation occurs.  So, when was the last time you looked at your SRA? It’s time to seriously analyze your current compliance posture. Ransomware groups don’t check whether you’re a small dental office or a 16-hospital health system before they attack, they check whether the door was left open. Time and again, OCR’s findings come back to the same root cause: organizations can’t secure what they haven’t even identified as a problem. Looking to review your current compliance standings? Meet with our team of experts for a complimentary educational consultation. 

Spencer Gifts HIPAA Fine
Abyde News, Fines, HIPAA

Spencer Gifts HIPAA Settlement: Ransomware, Risk Analysis, and What Comes Next

June 19, 2026 Penelope Schweitzer No comments yet

June 19, 2026   Quick Guide:  The Office for Civil Rights issued a major fine towards Spencer Gifts benefits plan. This fine reinforces that all HIPAA-regulated entities must have a thorough compliance program.    The Stats You Need to Know 76%: The percentage of large healthcare breaches now caused by hacking/IT incidents. $450,000: Financial settlement of this enforcement. 10,023: The number of individuals were impacted in this breach.  264%: The increase in ransomware-related breaches reported to the OCR since 2018.   When you think about Spencer’s, you likely picture the staple mall store with pop culture novelty gifts, not the latest HIPAA settlement enforcement headline.  Spencer Gifts LLC Flexible Benefits and Welfare Benefit Plans, or their employee benefits plan, reached a settlement with the Office for Civil Rights for $450,000 and a 2 year Corrective Action Plan (CAP).  This fine is a reminder that Covered Entities include all parties that create and utilize patient data, including health care plans. While they might not see patients traditionally, they still are responsible for keeping Protected Health Information (PHI) secure.    What Happened?   In response to employee complaints regarding access to their employee benefits portal, Spencer Gifts Health Plan discovered their systems were infiltrated with ransomware in November 2021. Malicious actors encrypted over 10,000 individuals’ PHI and demanded a ransom. The exposed data included names, phone numbers, social security numbers, and more, putting employees at risk.  The breach was reported in January 2022. After years of investigation, it was settled that the plan failed to meet basic HIPAA Security Rule requirements proactively.    The Compliance Gaps A common misconception is that an organization faces a financial penalty due to a breach. While the breach serves as the catalyst for the investigation, the OCR is looking to see if an organization has a thorough compliance program in place and made a genuine effort to protect patient data.  For instance, the health plan did not complete a Security Risk Analysis (SRA). This required assessment identifies all technical, administrative, and physical safeguards (and vulnerabilities) across your organization. By completing this document, your organization can address concerns before they become an issue. There’s no way to know where risks are unless they are properly reviewed.  Additionally, the plan did not have sufficient policies and procedures, nor trained staff adequately. Without sufficient policies and training, staff are left without the tools to recognize and respond to HIPAA threats before they escalate. As a result, Spencer Gifts now faces $450,000 in penalties and two years of government monitoring to ensure those missing requirements are finally implemented. And that figure doesn’t account for the years of investigation, legal fees, breach notification costs, and operational disruption that preceded the settlement.   The Biggest Takeaway This case isn’t only a lesson for retail organizations’ health plans, but it’s a warning for every HIPAA-regulated entity. The OCR can and will investigate any organization exposed for failing to meet HIPAA requirements, including small medical practices To be prepared before a cyberattack occurs, make sure your organization has: A completed and current Security Risk Analysis. A trained workforce that knows how to handle PHI Accessible policies and procedures staff can actually reference. An up-to-date compliance program.  Ready to strengthen your compliance program? Schedule a free educational consultation with our team today.

OCR Ransomware Settlements
Abyde News, Fines, HIPAA

OCR Ransomware Settlements: 4 Massive HIPAA Fines from April 2026 & How to Avoid Them

May 4, 2026 Penelope Schweitzer No comments yet

May 4, 2026   Quick Guide:  The Office for Civil Rights (OCR) just issued a massive wake-up call, announcing four simultaneous settlements totaling $1,165,000. The Stats You Need to Know 76%: The percentage of large healthcare breaches now caused by hacking/IT incidents. 427,000+: Total number of patients impacted across these four recent settlements. 264%: The increase in ransomware-related breaches reported to the OCR since 2018. The Office for Civil Rights (OCR) just announced a flurry of investigation settlements. At the root of the four that were announced: ransomware. Ransomware attacks continue to target healthcare facilities. As of last year, the OCR discovered that 76% of large breaches are due to hacking and IT shortcomings. Unfortunately, healthcare information is a goldmine for hackers, exposing sensitive data that can lead to identity theft, financial fraud, and compromised patient care. Breakdown & Lessons Learned Regional Women’s Health Group (Axia) The first settlement was regarding the Regional Women’s Health Group (Axia), an OBGYN network across five states. In this case, the organization submitted a breach report following a cyberattack that exposed over 37,000 patients. The settlement resulted in a $320,000 fine and a 2-year Corrective Action Plan (CAP). The Lesson: The OCR didn’t just fine them for being hacked; they reached a settlement because the healthcare organization failed to conduct a “thorough and accurate” Security Risk Analysis (SRA). If you don’t know where your vulnerabilities are, you can’t patch them. Unfortunately, hackers counted on this negligence and exploited it.  Assured Imaging This was the largest of the four fines, affecting a staggering 244,813 individuals. When a ransomware infection hit their servers, Assured Imaging, a medical imaging enterprise, reported a breach to the OCR. After a long investigation (the initial cyberattack occurred in 2020), and resulted in a $375,000 settlement and a 2-year CAP.  The Lesson: Beyond the initial ransomware attack, it was discovered that Assured had never completed an SRA. Additionally, the organization did not notify patients within 60 days of discovery of the breach. This is a direct violation of the Breach Notification Rule, which aims to allow patients to take control and mitigate risks as quickly as possible.  Consociate Health Consciate Health is the only Business Associate (BA) fine in the four. BAs continue to be under the OCR’s microscope, such as potentially needing to follow stricter requirements when handling patient data. Their breach started with a phishing attack that eventually led to the encryption of systems holding data for over 136,000 people. The BA discovered the ransomware six months after the initial phishing attack. Upon the OCR’s further investigation, the SRA was found to be insufficient. The organization paid a $225,000 settlement and entered into a 2-year CAP.  The Lesson: Human error (phishing) is the most common entry point for ransomware. Constant employee training is just as important as a strong firewall. Additionally, just because a BA doesn’t directly work with patients doesn’t mean it isn’t their responsibility to keep patient data secure.  SG Health Plan Even employee benefit plans are regulated under the Health Insurance Portability and Accountability Act (HIPAA). SG Health Plan, associated with a Connecticut energy provider, reported that the data of 9,316 members were exposed following a ransomware attack. It was discovered that the organization did not complete an extensive SRA. The benefit plan entered a settlement with the OCR for $245,000 and a 2-year CAP.  The Lesson: This settlement highlights that HIPAA applies to corporate health plans just as much as it does to traditional healthcare providers. Additionally, every organization that handles Protected Health Information (PHI) must complete an SRA.  The Bottom Line The OCR isn’t fining practices for ransomware attacks, but for being ill-prepared.  However, it is easier said than done to ensure your organization is secure in protecting patient data and complying with HIPAA.  Proactively implementing the HIPAA Security Rule is your opportunity to mitigate the impacts of a cyberattack. Waiting until the ransom note appears on your screen is a million-dollar mistake. Want to see what you might be missing?  Run a 5-Minute HIPAA Gap Assessment and protect your practice today! 

  • Facebook
  • Instagram
  • LinkedIn
  • YouTube
Abyde Logo

1.800.594.0883 | info@abyde.com

Automated HIPAA and OSHA Compliance

Our Reviews

From Our Blog
  • Don’t Get Caught Off Guard: HIPAA Audits are Back!
  • Don’t Be a Statistic: Why OSHA Compliance Matters in Healthcare
  • What Money Doesn’t Cover: The True Price of HIPAA Non-Compliance
  • HIPAA: It’s Not Just a Training – Your Guide to Continuous Compliance
Solutions
  • HIPAA for Covered Entities
  • OSHA for Healthcare
  • HIPAA for Business Associates
  • SRA for Covered Entities
  • Abyde Incident Response Program
  • Abyde Reseller Program
Resources
  • News
  • Events
  • Partners
  • HIPAA Badges
  • OSHA Badges
  • Learning Center
  • Compliance FAQs
Company
  • About Us
  • Who We Serve
  • Pricing
  • Contact Us
  • Newsletter
  • Jobs
  • COPYRIGHT © 2026 ABYDE
  • |

  • TERMS & CONDITIONS
  • |

  • PRIVACY POLICY
  • |

  • SECURITY MEASURES
  • |

  • E-SIGNATURE TERMS