Skip to content
  • About Us
    • Who We Serve
  • Solutions
    • HIPAA for Covered Entities
    • OSHA for Healthcare
    • HIPAA for Business Associates
    • SRA for Covered Entities
    • Abyde Incident Response Program
    • Abyde Reseller Program
  • Resources
  • News
  • Events
  • Partners
  • Contact Us
  • Login
    • HIPAA for Covered Entities
    • OSHA for Healthcare
    • HIPAA for Business Associates
    • SRA for Covered Entities
SIGN UP
BOOK A DEMO

October 2026

Dental Practice HIPAA Settlement
Abyde News, Fines, HIPAA

What Every Dental Practice Can Learn From the $140K Shen Smiles Settlement

October 9, 2026 Penelope Schweitzer No comments yet

October 9, 2026 The latest HIPAA penalty doesn’t involve a hospital system or a massive ransomware attack. It involves a practice that probably looks a lot like yours. Dr. Linda Shen is the owner of Shen Smiles, a solo dental practice with one location in Drums, Pennsylvania. It all started with one patient asking for their health records. It ended with a $140,000 penalty and a much closer look at how the practice handled HIPAA. The lesson? Every HIPAA-regulated practice, big or small, can face enforcement. What happened? It’s unclear when the patient first asked for their records, but patient records need to be provided within 30 days from the initial request. In April 2020, the patient’s attorney filed a complaint with the Office for Civil Rights (OCR). The patient had asked for their health records multiple times and never got it. Once OCR started digging, the missed request turned out to be just the beginning. Patient records weren’t properly maintained, staff had never received formal HIPAA Privacy Rule training, and there were no policies for handling patient requests. Dr. Shen admitted that the records were never provided because a former employee had taken them. That’s another violation, this theft is a breach, which means it needed to be reported to the OCR, patients needed to be notified, and given options to protect themselves (such as credit monitoring). These are baseline requirements every Covered Entity is expected to have in place. No compliance framework, like policies and training, means no HIPAA playbook, so when a patient asks for records (or records go missing), staff is unprepared and unaware how to handle the situation. In July 2024, OCR proposed a $140,000 Civil Money Penalty. Dr. Shen appealed, but ultimately settled on the full amount. The Takeaway for Practices Patient access has been an OCR priority for years through its HIPAA Right of Access Initiative. And as this case shows, one complaint is all it takes to open the door to a review of your entire compliance program. Now is the time to ask: Do we have written HIPAA policies our team can find? Do we have a process to answer every record request within 30 days? Can we prove every team member has completed HIPAA training? If any of those gave you pause, now’s the time to fix it, before OCR comes asking. Looking for the first step? Meet with one of our compliance experts to see where you currently stand.

Recent Posts

  • What Every Dental Practice Can Learn From the $140K Shen Smiles Settlement
  • $700K HIPAA Settlement: What the Ambry Genetics Phishing Breach Teaches Every Practice
  • Right of Access Enforcement Hits Eye Care: Inside the Azul Vision Settlement
  • What OSF Healthcare’s Ransomware Fine Teaches Every Practice About SRAs
  • Spencer Gifts HIPAA Settlement: Ransomware, Risk Analysis, and What Comes Next

Recent Comments

No comments to show.

Archives

  • October 2026
  • September 2026
  • August 2026
  • June 2026
  • May 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • September 2019
  • October 2018
  • July 2018
  • May 2018
  • November 2017
  • April 2017

Categories

  • Abyde News
  • Audits
  • Best Practices
  • Business Associates
  • Cybersecurity
  • Fines
  • HIPAA
  • Legislation
  • OSHA
  • Partner News
  • Facebook
  • Instagram
  • LinkedIn
  • YouTube
Abyde Logo

1.800.594.0883 | info@abyde.com

Automated HIPAA and OSHA Compliance

Our Reviews

From Our Blog
  • Don’t Get Caught Off Guard: HIPAA Audits are Back!
  • Don’t Be a Statistic: Why OSHA Compliance Matters in Healthcare
  • What Money Doesn’t Cover: The True Price of HIPAA Non-Compliance
  • HIPAA: It’s Not Just a Training – Your Guide to Continuous Compliance
Solutions
  • HIPAA for Covered Entities
  • OSHA for Healthcare
  • HIPAA for Business Associates
  • SRA for Covered Entities
  • Abyde Incident Response Program
  • Abyde Reseller Program
Resources
  • News
  • Events
  • Partners
  • HIPAA Badges
  • OSHA Badges
  • Learning Center
  • Compliance FAQs
Company
  • About Us
  • Who We Serve
  • Pricing
  • Contact Us
  • Newsletter
  • Jobs
  • COPYRIGHT © 2026 ABYDE
  • |

  • TERMS & CONDITIONS
  • |

  • PRIVACY POLICY
  • |

  • SECURITY MEASURES
  • |

  • E-SIGNATURE TERMS