Skip to content
  • About Us
    • Who We Serve
  • Solutions
    • HIPAA for Covered Entities
    • OSHA for Healthcare
    • HIPAA for Business Associates
    • SRA for Covered Entities
    • Abyde Incident Response Program
    • Abyde Reseller Program
  • Resources
  • News
  • Events
  • Partners
  • Contact Us
  • Login
    • HIPAA for Covered Entities
    • OSHA for Healthcare
    • HIPAA for Business Associates
    • SRA for Covered Entities
SIGN UP
BOOK A DEMO

Latest OCR Cybersecurity Updates

July 1, 2021

With Cyber Security Awareness Month right around the corner, the multiple cyber alerts issued by the Office for Civil Rights (OCR) in the month of June serve as a perfect preamble for the importance of prioritizing data protection all year round. These government-issued Cyber Alerts have become all too familiar in the healthcare industry, with the past year seemingly filled with emergency directives and scam tactics to be aware of. So with healthcare data breaches on the rise and the most recent warnings of a heightened risk of ransomware and IT system vulnerabilities – ensuring your organization has the necessary programs in place is essential to avoid falling victim.

What did the most recent Cyber Alerts cover? 

In early June, the White House and Cybersecurity and Infrastructure Agency (CISA) released a memo titled “What We Urge You to Do to Protect Against the Threat of Ransomware.” This alert urged healthcare organizations to take appropriate action in protecting against ransomware threats and covered several best practices that providers can take to enhance cybersecurity including:

  • Implementing multi-factor authentication for network and device login and passwords.
  • Ensuring all data is encrypted when it is both sent and stored.
  • Improving endpoint detection and response to identify any malicious activity early on.
  • Regularly backing up data and keeping these backups offline.
  • Updating and patching systems promptly to best maintain the security of operating systems as new threats evolve.
  • Testing disaster recovery plans on an ongoing basis before an incident occurs.
  • Evaluating organizational security teams’ practices by using a third-party tester to determine cybersecurity readiness.
  • Segmenting company networks so that if a network is compromised, the threat is better mitigated. This could mean separating a labs IT network from the one used in your main office to help isolate the data compromised and system downtime if a threat were to occur.

While keeping up with the above steps should be done on a regular basis, the more recent OCR notice covers additional vulnerabilities organizations should be aware of. According to the memo shared on June 25, 2021 – Eclypsium Security Researchers have discovered a vulnerability in the Dell BIOSConnect feature available on over 180 models of consumer and business devices. Dell urges all customers to ensure that their devices are updated to the latest version and provided a full list of impacted devices and steps to address the vulnerability that can be found here. 

Additionally, this memo also included an advisory from CISA due to the multiple vulnerabilities found in the ZOLL Defibrillator Dashboard. The agency warns that these vulnerabilities may allow a remote user to take control of an affected system and emphasizes that all organizations should review the ICS Medical Advisory and apply the recommended mitigations. 

So now what? 

Well, for any healthcare organization of any size – data breaches and cyberattacks are becoming more and more of a concern. Implementing the necessary technical safeguards,  following guidance on ransomware prevention, and keeping all devices and IT systems up to date with the latest version is key to steering clear of heightened vulnerabilities like the ones outlined in recent government memos. Unfortunately, as technology and threat actor tactics continue to evolve, these new and increasing threats don’t seem to be going away anytime soon. So keeping your practice and your patients’ data protected in the long run starts with having both a security AND compliance program in place now.

RECENT POSTS

  • OSF Healthcare HIPAA Settlement
    What OSF Healthcare's Ransomware Fine Teaches Every Practice About SRAs
  • Spencer Gifts HIPAA Fine
    Spencer Gifts HIPAA Settlement: Ransomware, Risk Analysis, and What Comes Next
  • OCR Ransomware Settlements
    OCR Ransomware Settlements: 4 Massive HIPAA Fines from April 2026 & How to Avoid Them
PrevPreviousYour Organizations’ HIPAA Rulebook: Policies & Procedures
NextAbyde and Smile Source partner to deliver leading HIPAA compliance solutions to private practice dental professionalsNext

Related posts

OSF Healthcare HIPAA Settlement
Abyde News, Fines, HIPAA

What OSF Healthcare’s Ransomware Fine Teaches Every Practice About SRAs

August 5, 2026 Penelope Schweitzer No comments yet

August 5, 2026 The latest HIPAA fine is another clear reminder that ransomware attacks are, unfortunately, here to stay in the healthcare industry. A settlement involving the OSF Healthcare System was recently announced by the Office for Civil Rights (OCR). As an enterprise healthcare provider in the midwest, the organization serves 174 locations, including 16 hospitals – a prime target for a ransomware attack.    So, what happened?  In April 2021, OSF discovered that they joined the unlucky club of ransomware victims when a malicious actor deployed Nephilim, a ransomware strain made to target larger organizations. Once the ransomware infected OSF systems, the hacker demanded payment or patient Protected Health Information (PHI) would be leaked online. In this attack, sensitive information like financial account information, driver’s license numbers, medical record numbers, and more, were all exposed. Over 53,000 patient records were exposed in this attack.  When ransomware attacks in healthcare have soared 278% in recent years, it’s more of a when then an if your organization doesn’t have the right safeguards in place.  While the breach was discovered in April, OSF healthcare reported the breach to the OCR in October. The OCR took it from there, digging into what precautions (or lack thereof) let this happen.  What did the OCR discover? If you’ve read any of our other fine breakdowns, you already know where this is going: another missing Security Risk Analysis (SRA).  The SRA is a required document every HIPAA-regulated entity (ie: every practice and their Business Associates that handle patient information) needs to complete. The SRA is a thorough review of the physical, technical, and administrative safeguards in place to prevent PHI ending up in the wrong hands. While the OCR didn’t specify exactly how the ransomware got into OSF’s system, a technical safeguard vulnerability was very likely the entry point. A proactive SRA could have flagged that gap before it turned into a major breach. In addition to missing this required documentation, OSF also took too long to report the breach to the OCR and notify affected patients. This is a direct violation of the Breach Notification Rule, which requires organizations to notify patients within 60 days of a discovered breach. Moreover, since the breach impacted more than 500 patients, OSF was also required to report this breach to the OCR within 2 months as well. Time is of the essence in every component of a breach, from securing systems to ensuring affected parties are aware to protect themselves and an over five month delay was unacceptable in the eyes of the OCR.    What was the result?  OSF’s settlement tops the list as the largest fine of the year, coming in at $552,250, plus government monitoring for the next two years.  It’s very important to note that this breach occurred in 2021, meaning that over five years were spent from the initial breach, to investigations, to the public press releases. Also, the average cost of a healthcare breach is over 7 million dollars –  from implementing secure systems, notifying patients, legal fees, and more. The Takeaway While the settlement payment and Corrective Action Plan (CAP) are just the cherries on top, this experience was a tremendous cost of time, money, and resources, highlighting the importance of making sure everything is secure before a situation occurs.  So, when was the last time you looked at your SRA? It’s time to seriously analyze your current compliance posture. Ransomware groups don’t check whether you’re a small dental office or a 16-hospital health system before they attack, they check whether the door was left open. Time and again, OCR’s findings come back to the same root cause: organizations can’t secure what they haven’t even identified as a problem. Looking to review your current compliance standings? Meet with our team of experts for a complimentary educational consultation. 

Cadia Healthcare HIPAA Fine
Abyde News, Fines, HIPAA

From Success Stories to HIPAA Violations: Cadia Healthcare’s $182K Lesson

October 6, 2025 Penelope Schweitzer No comments yet

October 6, 2025   Remember: sometimes, it’s not your story to tell.  While your practice might be excited to share the positive results of quality patient care, it’s your patients’ right to share their stories. Patients’ medical histories and treatment plans are considered Protected Health Information (PHI), and it’s your practice’s responsibility to safeguard all sensitive patient data.  Cadia Healthcare Facilities is the latest rehabilitation organization caught in the Office for Civil Rights’ (OCR) crosshairs after improperly disclosing patient health stories online. Notified by a patient complaint, the OCR investigated the organization and settled the violation with a $182,000 fine and a two-year Corrective Action Plan (CAP). A major financial and reputational hit, paired with thorough government monitoring, is a lesson learned for the organization.  The 20th fine of the year teaches healthcare practices the importance of HIPAA-compliant marketing, website management, and patient consent.    What Happened?  The rehabilitation organization implemented a Success Story section on its site, with 150 patients’ stories publicly highlighted on the page. This page had extensive PHI, including a patient’s name, image, conditions, treatment, and recovery plans.  While Cadia Healthcare Facilities utilized the website with good intentions, these Success Stories quickly turned into HIPAA horrors. The reason why? Missing HIPAA authorization forms for all 150 featured patients. Then, a patient contacted the OCR with concerns about their image being used without permission on the Cadia Healthcare Facilities website. That’s when the OCR discovered the rehabilitation organization’s noncompliant website and impermissible disclosures.  In addition to the fine and government monitoring, the organization must notify all impacted patients that their information was breached on its site, per the Breach Notification Rule.   Share Online Compliantly Posting your practice’s accomplishments online might be exciting, but your practice must handle it carefully.  Your practice must obtain a HIPAA authorization form before publicly sharing patients’ PHI. This includes before-and-after photos, testimonials, and, in this case, success stories. The forms must be written and specific, and patients can withdraw permission at any time.  Your practice’s online presence is likely a new patient’s first impression, so it’s essential to maintain and update your webpage. However, having more likes and views should never outweigh your commitment to compliance and patient protection. Are you confident your staff understands how HIPAA compliance extends to social media and other forms of marketing? With smart software, your practice can easily train and provide staff with the required documents for HIPAA-compliant social media use. The right compliance solution will empower your staff to handle HIPAA compliance with ease, allowing them to build an online presence while keeping patient data safe.  To learn more about HIPAA compliance for your practice, meet with a compliance expert today. 

Small Healthcare Practice HIPAA Fine
Abyde News, Fines, HIPAA

Small Size, Same Rules: HIPAA Fine Serves as Reminder for All Healthcare Providers

May 19, 2025 Penelope Schweitzer No comments yet

May 19, 2025   HIPAA compliance is not just a recommendation; it’s a requirement, no matter how small your organization is. The latest HIPAA fine is a testament to this, with Vision Upright MRI the latest practice to be penalized.  The small California MRI center experienced a significant breach, which exposed several violations in the fallout. Acting Office for Civil Rights (OCR) Director Anthony Archeval emphasized the widespread cybersecurity risks, noting that these threats impact healthcare providers of all sizes:  “Cybersecurity threats affect large and small covered healthcare providers.”  Vision Upright MRI was fined $5,000 and will now face a two-year Corrective Action Plan (CAP), being monitored by the OCR.  This fine showcases that no practice, big or small, must be followed to keep patient data safe.     What Happened? At the end of 2020, Vision Upright MRI experienced a breach in its systems due to an insecure server. This cybercrime exposed over 21,000 patients’ medical images, leading to the OCR’s investigation.  The investigation discovered that the MRI center had never completed a Security Risk Analysis (SRA). The SRA thoroughly examines a practice, reviewing all current safeguards to secure Protected Health Information (PHI). These safeguards can include physical barriers the practice has implemented, like locked doors and alarms, and the administrative techniques the practice follows, like routinely checking access to sensitive patient data.  The SRA is critical for a compliant practice and should be completed annually and after any breaches.  While the SRA is a fundamental requirement for a practice, it is unfortunately often overlooked. The OCR has implemented a Risk Analysis Initiative to ensure practices are completing this requirement, and has reinstated the audit program, reviewing if regulated entities are maintaining this document.  In addition to missing the SRA, Vision Upright MRI did not properly notify affected parties within 60 days, violating the Breach Notification Rule.  The Breach Notification Rule requires practices to notify patients within 60 days of discovering a breach, regardless of how many were impacted. This short timeline allows patients to take the necessary precautions for the safety of their data. The practice should also provide credit monitoring. Since this event impacted well over 500 patients, the threshold to consider the situation a large breach, Vision Upright MRI also needed to notify the media and the OCR within a 60-day timeline. Communicating this is imperative, allowing the OCR to swiftly begin its investigation and potentially affected patients to receive information through media channels. These serious missteps led to the monetary settlement and years of government monitoring.    Streamlining HIPAA Compliance Even a small practice doesn’t require overwhelming resources to be HIPAA compliant. The right compliance program can simplify HIPAA compliance. With smart solutions, the SRA can be completed easily, reviewing questions and potential vulnerabilities the practice faces. Additionally, breaches can be reported in intelligent software, with compliance experts assisting practices through alerting patients and the OCR.  Meet with an expert today to learn how to automate your compliance program.   

  • Facebook
  • Instagram
  • LinkedIn
  • YouTube
Abyde Logo

1.800.594.0883 | info@abyde.com

Automated HIPAA and OSHA Compliance

Our Reviews

From Our Blog
  • Don’t Get Caught Off Guard: HIPAA Audits are Back!
  • Don’t Be a Statistic: Why OSHA Compliance Matters in Healthcare
  • What Money Doesn’t Cover: The True Price of HIPAA Non-Compliance
  • HIPAA: It’s Not Just a Training – Your Guide to Continuous Compliance
Solutions
  • HIPAA for Covered Entities
  • OSHA for Healthcare
  • HIPAA for Business Associates
  • SRA for Covered Entities
  • Abyde Incident Response Program
  • Abyde Reseller Program
Resources
  • News
  • Events
  • Partners
  • HIPAA Badges
  • OSHA Badges
  • Learning Center
  • Compliance FAQs
Company
  • About Us
  • Who We Serve
  • Pricing
  • Contact Us
  • Newsletter
  • Jobs
  • COPYRIGHT © 2026 ABYDE
  • |

  • TERMS & CONDITIONS
  • |

  • PRIVACY POLICY
  • |

  • SECURITY MEASURES
  • |

  • E-SIGNATURE TERMS