Skip to content
  • About Us
    • Who We Serve
  • Solutions
    • HIPAA for Covered Entities
    • OSHA for Healthcare
    • HIPAA for Business Associates
    • SRA for Covered Entities
    • Abyde Incident Response Program
    • Abyde Reseller Program
  • Resources
  • News
  • Events
  • Partners
  • Contact Us
  • Login
    • HIPAA for Covered Entities
    • OSHA for Healthcare
    • HIPAA for Business Associates
    • SRA for Covered Entities
SIGN UP
BOOK A DEMO

The Department of Health and Human Services Appoints Melanie Fontes Rainer as the New Office for Civil Rights Director

September 19, 2022

Did you check the news??? There’s a new sheriff in town and her name is Melanie Fontes Rainer! Recently announced, the Department of Health and Human Services (HHS) has appointed former Acting Director, Melanie Fontes Rainer, as the new Director of the Office for Civil Rights (OCR). Fontes Rainer has extensive experience in her career, serving as an Acting Director for the OCR and before that Counselor to Secretary Becerra. 

Secretary Becerra stated, “Melanie has devoted her entire professional career to public service and has worked tirelessly to ensure that health care is accessible, affordable, and available to all, no matter where you live or who you are.”

Fontes Rainer brings over 10 years of experience in civil rights, healthcare policy, and patient privacy. She was also involved in the 21st Century Cures Act, the Affordable Care Act, and the No Suprise Act. Fontes Rainer took part in ground-breaking settlements and created the first office that focused on health care rights and access in California. Melanie’s background, combined with her passion, will prepare her for the challenges she will face in her new role as OCR Director. 

It is important to take into account that after Lisa J. Pino, former OCR Director, was appointed last year, we saw a surge in enforcement cases right away. Only a few months into Pino’s appointment as director, the OCR announced five Right of Access settlements in one day. This year we have already seen 17 including a record-breaking day with 11 settlements announced in just one day alone. With settlements totaling $1,992,140 already in 2022, the OCR clearly isn’t done yet.

As we can see, between HIPAA violations, cybersecurity issues, and personal information privacy, practices continue to face challenges this year. But we can also see that Fontes Rainer is here to help, bringing years of expertise and fiery passion to the table. She enforces healthcare regulations, promotes healthy practice operations, and protects patient health information across the country. With years of dedication to civil rights and medical privacy, we can definitely expect to see a lot of settlements surfacing with Fontes Rainer in town.

 

RECENT POSTS

  • OSF Healthcare HIPAA Settlement
    What OSF Healthcare's Ransomware Fine Teaches Every Practice About SRAs
  • Spencer Gifts HIPAA Fine
    Spencer Gifts HIPAA Settlement: Ransomware, Risk Analysis, and What Comes Next
  • OCR Ransomware Settlements
    OCR Ransomware Settlements: 4 Massive HIPAA Fines from April 2026 & How to Avoid Them
PrevPreviousOCR Settles Case Concerning Improper Disposal of Protected Health Information
NextOCR Settles Three Cases with Dental Practices for Patient Right of Access under HIPAANext

Related posts

OSF Healthcare HIPAA Settlement
Abyde News, Fines, HIPAA

What OSF Healthcare’s Ransomware Fine Teaches Every Practice About SRAs

August 5, 2026 Penelope Schweitzer No comments yet

August 5, 2026 The latest HIPAA fine is another clear reminder that ransomware attacks are, unfortunately, here to stay in the healthcare industry. A settlement involving the OSF Healthcare System was recently announced by the Office for Civil Rights (OCR). As an enterprise healthcare provider in the midwest, the organization serves 174 locations, including 16 hospitals – a prime target for a ransomware attack.    So, what happened?  In April 2021, OSF discovered that they joined the unlucky club of ransomware victims when a malicious actor deployed Nephilim, a ransomware strain made to target larger organizations. Once the ransomware infected OSF systems, the hacker demanded payment or patient Protected Health Information (PHI) would be leaked online. In this attack, sensitive information like financial account information, driver’s license numbers, medical record numbers, and more, were all exposed. Over 53,000 patient records were exposed in this attack.  When ransomware attacks in healthcare have soared 278% in recent years, it’s more of a when then an if your organization doesn’t have the right safeguards in place.  While the breach was discovered in April, OSF healthcare reported the breach to the OCR in October. The OCR took it from there, digging into what precautions (or lack thereof) let this happen.  What did the OCR discover? If you’ve read any of our other fine breakdowns, you already know where this is going: another missing Security Risk Analysis (SRA).  The SRA is a required document every HIPAA-regulated entity (ie: every practice and their Business Associates that handle patient information) needs to complete. The SRA is a thorough review of the physical, technical, and administrative safeguards in place to prevent PHI ending up in the wrong hands. While the OCR didn’t specify exactly how the ransomware got into OSF’s system, a technical safeguard vulnerability was very likely the entry point. A proactive SRA could have flagged that gap before it turned into a major breach. In addition to missing this required documentation, OSF also took too long to report the breach to the OCR and notify affected patients. This is a direct violation of the Breach Notification Rule, which requires organizations to notify patients within 60 days of a discovered breach. Moreover, since the breach impacted more than 500 patients, OSF was also required to report this breach to the OCR within 2 months as well. Time is of the essence in every component of a breach, from securing systems to ensuring affected parties are aware to protect themselves and an over five month delay was unacceptable in the eyes of the OCR.    What was the result?  OSF’s settlement tops the list as the largest fine of the year, coming in at $552,250, plus government monitoring for the next two years.  It’s very important to note that this breach occurred in 2021, meaning that over five years were spent from the initial breach, to investigations, to the public press releases. Also, the average cost of a healthcare breach is over 7 million dollars –  from implementing secure systems, notifying patients, legal fees, and more. The Takeaway While the settlement payment and Corrective Action Plan (CAP) are just the cherries on top, this experience was a tremendous cost of time, money, and resources, highlighting the importance of making sure everything is secure before a situation occurs.  So, when was the last time you looked at your SRA? It’s time to seriously analyze your current compliance posture. Ransomware groups don’t check whether you’re a small dental office or a 16-hospital health system before they attack, they check whether the door was left open. Time and again, OCR’s findings come back to the same root cause: organizations can’t secure what they haven’t even identified as a problem. Looking to review your current compliance standings? Meet with our team of experts for a complimentary educational consultation. 

Cadia Healthcare HIPAA Fine
Abyde News, Fines, HIPAA

From Success Stories to HIPAA Violations: Cadia Healthcare’s $182K Lesson

October 6, 2025 Penelope Schweitzer No comments yet

October 6, 2025   Remember: sometimes, it’s not your story to tell.  While your practice might be excited to share the positive results of quality patient care, it’s your patients’ right to share their stories. Patients’ medical histories and treatment plans are considered Protected Health Information (PHI), and it’s your practice’s responsibility to safeguard all sensitive patient data.  Cadia Healthcare Facilities is the latest rehabilitation organization caught in the Office for Civil Rights’ (OCR) crosshairs after improperly disclosing patient health stories online. Notified by a patient complaint, the OCR investigated the organization and settled the violation with a $182,000 fine and a two-year Corrective Action Plan (CAP). A major financial and reputational hit, paired with thorough government monitoring, is a lesson learned for the organization.  The 20th fine of the year teaches healthcare practices the importance of HIPAA-compliant marketing, website management, and patient consent.    What Happened?  The rehabilitation organization implemented a Success Story section on its site, with 150 patients’ stories publicly highlighted on the page. This page had extensive PHI, including a patient’s name, image, conditions, treatment, and recovery plans.  While Cadia Healthcare Facilities utilized the website with good intentions, these Success Stories quickly turned into HIPAA horrors. The reason why? Missing HIPAA authorization forms for all 150 featured patients. Then, a patient contacted the OCR with concerns about their image being used without permission on the Cadia Healthcare Facilities website. That’s when the OCR discovered the rehabilitation organization’s noncompliant website and impermissible disclosures.  In addition to the fine and government monitoring, the organization must notify all impacted patients that their information was breached on its site, per the Breach Notification Rule.   Share Online Compliantly Posting your practice’s accomplishments online might be exciting, but your practice must handle it carefully.  Your practice must obtain a HIPAA authorization form before publicly sharing patients’ PHI. This includes before-and-after photos, testimonials, and, in this case, success stories. The forms must be written and specific, and patients can withdraw permission at any time.  Your practice’s online presence is likely a new patient’s first impression, so it’s essential to maintain and update your webpage. However, having more likes and views should never outweigh your commitment to compliance and patient protection. Are you confident your staff understands how HIPAA compliance extends to social media and other forms of marketing? With smart software, your practice can easily train and provide staff with the required documents for HIPAA-compliant social media use. The right compliance solution will empower your staff to handle HIPAA compliance with ease, allowing them to build an online presence while keeping patient data safe.  To learn more about HIPAA compliance for your practice, meet with a compliance expert today. 

Ransomware Data Breach in Healthcare
Abyde News, Fines, HIPAA

Ransomware Strikes Again: What the Latest HIPAA Fine Teaches Us

July 28, 2025 Penelope Schweitzer No comments yet

July 28, 2025   Healthcare’s cybercrime nightmare just got more expensive. With over half a million dollars in fines and the second HIPAA ransomware fine issued this month alone, it’s time to acknowledge the serious threat cybercrimes pose to healthcare.  The Office for Civil Rights (OCR)  just announced its latest HIPAA fine, following a ransomware attack affecting a surgery center in New York, totalling $250,000 and placing the practice under a two-year Corrective Action Plan (CAP). The two-year period includes constant government monitoring, ensuring the healthcare provider has taken action to mitigate risks and secure Protected Health Information (PHI).  Here’s where things get interesting. Upon further inspection, the exact ransomware variant, PYSA, explicitly targets the healthcare industry. Think about it: cybercriminals know the absolute treasure trove of sensitive patient data a healthcare organization holds.  As malicious actors know the importance of patient health records, your practice must be extra vigilant when handling PHI.    What Happened? In March 2021, an unauthorized actor gained access to the networks of Specialty Surgery Center of Central New York (also known as Syracuse ASC, LLC). The hacker deployed ransomware in the organization’s networks for over two weeks. This ransomware exposed nearly 25,000 patient records, with access to Social Security numbers, addresses, health histories, and more.  Syracuse ASC, LLC, notified the OCR of this breach in October 2021, over six months after the initial intrusion. This wait violated the HIPAA Breach Notification Rule. Given the massive breach, the healthcare provider had to notify the OCR, patients, media, and potentially the State Attorney General within 60 days of discovery. Notifying these parties allows patients to take control and explore options for protecting and monitoring their data post-breach. Additionally, it could have expedited the OCR and State officials’ investigations into the extent of the ransomware attack. During the investigation process, the OCR made another startling discovery: no Security Risk Analysis (SRA) was in place.  A thorough SRA is required to maintain your practice’s security. By examining existing safeguards, you can identify and address vulnerabilities proactively before they cause problems. This practice learned the hard way about a common HIPAA pitfall: missing an SRA. Due to this, a hacker infiltrated and exploited the vulnerability of an insecure network, leading to a quarter-million-dollar fine.    Protecting Your Practice Against Ransomware Hackers have discovered a gold mine with medical records costing upwards of $1000 on the dark web, compared to the average credit card number fetching 25¢. When hackers directly target healthcare practices, your compliance program and safeguards must be in order.  Proactive compliance is key to the security of PHI. Your practice can mitigate and minimize ransomware threats by using the right compliance solutions and robust IT assistance. With the right software, it’s easy to streamline pillars of HIPAA compliance, like the SRA, identifying issues early to avoid risking your patients.  Meet with our team of experts to learn more about how you can simplify HIPAA compliance for your practice. 

  • Facebook
  • Instagram
  • LinkedIn
  • YouTube
Abyde Logo

1.800.594.0883 | info@abyde.com

Automated HIPAA and OSHA Compliance

Our Reviews

From Our Blog
  • Don’t Get Caught Off Guard: HIPAA Audits are Back!
  • Don’t Be a Statistic: Why OSHA Compliance Matters in Healthcare
  • What Money Doesn’t Cover: The True Price of HIPAA Non-Compliance
  • HIPAA: It’s Not Just a Training – Your Guide to Continuous Compliance
Solutions
  • HIPAA for Covered Entities
  • OSHA for Healthcare
  • HIPAA for Business Associates
  • SRA for Covered Entities
  • Abyde Incident Response Program
  • Abyde Reseller Program
Resources
  • News
  • Events
  • Partners
  • HIPAA Badges
  • OSHA Badges
  • Learning Center
  • Compliance FAQs
Company
  • About Us
  • Who We Serve
  • Pricing
  • Contact Us
  • Newsletter
  • Jobs
  • COPYRIGHT © 2026 ABYDE
  • |

  • TERMS & CONDITIONS
  • |

  • PRIVACY POLICY
  • |

  • SECURITY MEASURES
  • |

  • E-SIGNATURE TERMS