Skip to content
  • About Us
    • Who We Serve
  • Solutions
    • HIPAA for Covered Entities
    • OSHA for Healthcare
    • HIPAA for Business Associates
    • SRA for Covered Entities
    • Abyde Incident Response Program
    • Abyde Reseller Program
  • Resources
  • News
  • Events
  • Partners
  • Contact Us
  • Login
    • HIPAA for Covered Entities
    • OSHA for Healthcare
    • HIPAA for Business Associates
    • SRA for Covered Entities
SIGN UP
BOOK A DEMO

A New York Health Center’s Case is Denied Under OSH Act

November 28, 2022

Hey, ref – blow the whistle already! Back in June of 2021, the U.S. Department of Labor filed suit against a New York health center due to an alleged violation of the OSH Act. It was reported that the NY health center suspended and later terminated an employee who had reported personal concerns about exposure to COVID-19. The employee, also known as the whistleblower did so under the OSH Act, which protects workers from retaliation when reporting a hazardous work condition. 

The health center proceeded to file a motion in October of 2021, preventing the department from seeking damages for the whistleblower. Fast forward to September of this year, a federal court has rejected the health center’s case under the protection of the OSH Act. 

Regional Solicitor of Labor, Jeffrey Rogoff adds, “This is a significant decision reaffirming the U.S. Department of Labor’s independent authority to pursue legal actions and relief for employees in the name of the public interest. The Office of the Solicitor of Labor will continue to aggressively bring cases seeking to vindicate the rights of whistleblowers, who are essential to the proper functioning of laws protecting the health and safety, wages, and wellbeing of the American workforce.” 
More investigations from the OSHA’s Division of Whistleblower Protection Programs are underway in New York. So what can we take away from this? As a reminder, the Whistleblower Protection Program enforces the provisions of more than 20 federal laws. These protect your employees from retaliation from raising or reporting their concerns about hazards of violations of various workplace safety and health. Make sure your office is a safe place where employees can voice their concerns, but more importantly you are taking the proper steps upfront to ensure your practice meets the necessary safety and health standards.

RECENT POSTS

  • Spencer Gifts HIPAA Fine
    Spencer Gifts HIPAA Settlement: Ransomware, Risk Analysis, and What Comes Next
  • OCR Ransomware Settlements
    OCR Ransomware Settlements: 4 Massive HIPAA Fines from April 2026 & How to Avoid Them
  • OSHA 2026 GHS Deadlines
    2026 OSHA HazCom Deadlines: How the GHS Update Impacts Your Practice
PrevPreviousAbyde Honored in 2023 Seminole 100
NextToothpaste, Baseball, and ePHINext

Related posts

Spencer Gifts HIPAA Fine
Abyde News, Fines, HIPAA

Spencer Gifts HIPAA Settlement: Ransomware, Risk Analysis, and What Comes Next

June 19, 2026 Penelope Schweitzer No comments yet

June 19, 2026   Quick Guide:  The Office for Civil Rights issued a major fine towards Spencer Gifts benefits plan. This fine reinforces that all HIPAA-regulated entities must have a thorough compliance program.    The Stats You Need to Know 76%: The percentage of large healthcare breaches now caused by hacking/IT incidents. $450,000: Financial settlement of this enforcement. 10,023: The number of individuals were impacted in this breach.  264%: The increase in ransomware-related breaches reported to the OCR since 2018.   When you think about Spencer’s, you likely picture the staple mall store with pop culture novelty gifts, not the latest HIPAA settlement enforcement headline.  Spencer Gifts LLC Flexible Benefits and Welfare Benefit Plans, or their employee benefits plan, reached a settlement with the Office for Civil Rights for $450,000 and a 2 year Corrective Action Plan (CAP).  This fine is a reminder that Covered Entities include all parties that create and utilize patient data, including health care plans. While they might not see patients traditionally, they still are responsible for keeping Protected Health Information (PHI) secure.    What Happened?   In response to employee complaints regarding access to their employee benefits portal, Spencer Gifts Health Plan discovered their systems were infiltrated with ransomware in November 2021. Malicious actors encrypted over 10,000 individuals’ PHI and demanded a ransom. The exposed data included names, phone numbers, social security numbers, and more, putting employees at risk.  The breach was reported in January 2022. After years of investigation, it was settled that the plan failed to meet basic HIPAA Security Rule requirements proactively.    The Compliance Gaps A common misconception is that an organization faces a financial penalty due to a breach. While the breach serves as the catalyst for the investigation, the OCR is looking to see if an organization has a thorough compliance program in place and made a genuine effort to protect patient data.  For instance, the health plan did not complete a Security Risk Analysis (SRA). This required assessment identifies all technical, administrative, and physical safeguards (and vulnerabilities) across your organization. By completing this document, your organization can address concerns before they become an issue. There’s no way to know where risks are unless they are properly reviewed.  Additionally, the plan did not have sufficient policies and procedures, nor trained staff adequately. Without sufficient policies and training, staff are left without the tools to recognize and respond to HIPAA threats before they escalate. As a result, Spencer Gifts now faces $450,000 in penalties and two years of government monitoring to ensure those missing requirements are finally implemented. And that figure doesn’t account for the years of investigation, legal fees, breach notification costs, and operational disruption that preceded the settlement.   The Biggest Takeaway This case isn’t only a lesson for retail organizations’ health plans, but it’s a warning for every HIPAA-regulated entity. The OCR can and will investigate any organization exposed for failing to meet HIPAA requirements, including small medical practices To be prepared before a cyberattack occurs, make sure your organization has: A completed and current Security Risk Analysis. A trained workforce that knows how to handle PHI Accessible policies and procedures staff can actually reference. An up-to-date compliance program.  Ready to strengthen your compliance program? Schedule a free educational consultation with our team today.

MMG Fusion HIPAA Settlement
Abyde News, Fines, HIPAA

15 Million Reasons to Review Your Business Associates: Lessons from the MMG Fusion Settlement

March 6, 2026 Penelope Schweitzer No comments yet

March 6, 2026 They say a mistake ignored is a disaster in the making. For one dental software provider, a 2020 breach became a 15-million-patient nightmare in 2026. MMG Fusion LLC, a dental marketing software business in Maryland, is in the crosshairs of the OCR and the subject of the latest HIPAA enforcement action. MMG agreed to a $10,000 settlement and a 3-year Corrective Action Plan (CAP).  The latest HIPAA settlement, and the 12th Enforcement Action in the Office for Civil Rights (OCR) Risk Analysis Initiative, highlighted the importance of completing a thorough Security Risk Analysis (SRA), proper Breach Notification, and choosing the right Business Associate (BA).  What Happened?  In December 2020, a malicious actor infiltrated MMG’s systems. Over 15 million patients’ Protected Health Information (PHI) was exposed in the cybercrime and leaked to the dark web.  Under the HIPAA Breach Notification Rule, a BA must notify affected Covered Entities (the dental practices) within 60 days of discovering a breach. However, the OCR didn’t learn about this 2020 incident until a complaint was filed in March 2023, more than two years later. The investigation uncovered a critical flaw: MMG Fusion lacked a compliant Security Risk Analysis (SRA). The SRA is a comprehensive review of an organization’s physical, technical, and administrative safeguards to protect PHI. A thorough SRA likely would have identified the very system vulnerabilities that the hackers exploited in 2020. Although the OCR factored in MMG’s “small business” status when determining the $10,000 fine, this amount does not account for the years the investigation took, the accumulated costs of legal counsel, stress, and reputational damage that occurred before the fine was made public. Additionally, MMG will also need to report to the OCR for 3 years in accordance with the CAP settlement.  Streamline Your Compliance This case highlights three non-negotiable pillars for every HIPAA-regulated entity: compliant HIPAA risk assessments, timely breach notification to the OCR and impacted parties, and choosing the right business partner to handle your sensitive information.  Managing vendors and staying on top of SRAs is overwhelming for a busy healthcare organization.  Modern software solutions automate the SRA process and generate compliant Business Associate Agreements (BAAs) for Covered Entities and BAs to use, ensuring both parties are held accountable.  Ready to learn more? Meet with an expert today!

Top of the World Ranch Treatment Center HIPAA Settlement
Abyde News, Fines, HIPAA

2026 HIPAA Compliance Alert: $103,000 Settlement for Risk Analysis Failure

February 23, 2026 Penelope Schweitzer No comments yet

February 23, 2026   The Office for Civil Rights (OCR) is back with a massive settlement to start 2026.  A rehab center in Illinois, Top of the World Ranch Treatment Center (TWRTC), recently agreed to a $103,000 and 2-year Corrective Action Plan (CAP) settlement following a security breach that exposed major security vulnerabilities. This settlement is also the 11th enforcement of the Risk Analysis Initiative.  The Top of the World Ranch Treatment Center HIPAA settlement was announced just days after the OCR officially enacted the Part 2 changes to the Notice of Privacy Practices. As of Feb 16, all Covered Entities, regardless of scope of practice, must update their Notices of Privacy Practices (NPP) to include special provisions regarding the handling of Substance Use Disorder (SUD) Protected Health Information (PHI).    What Happened?  In March 2023, an employee’s email account was compromised in a phishing attack, exposing fewer than 2,000 records. In the world of healthcare data breaches, where numbers often reach the millions, this was a relatively small but still severe incident. However, the OCR’s enforcement was not based on the size of the breach, but on missing paperwork. This breach report initiated an investigation that led the OCR to find the SUD facility had failed to complete a compliant Security Risk Analysis (SRA). The SRA is the foundation of a HIPAA-compliant practice and an extensive assessment of the potential vulnerabilities your practice might face. The SRA reviews the administrative, physical, and technical safeguards your practice must have in place.  Since TWRTC hadn’t completed this proactive assessment, they missed the specific vulnerabilities in their technical defenses that eventually allowed a phishing email to succeed.   The Bottom Line The Top of the World Ranch Treatment Center HIPAA settlement proves that the OCR doesn’t punish based on how ‘big’ a mistake is, but for a lack of preparation. Breaches happen, but your team’s readiness and response are what determine whether you face an enforcement action. You might think your practice is too small to be a target, but this settlement shows that if you have a breach, no matter the size, the first thing the OCR will ask for is your SRA. If you don’t have it, the legal repercussions could be far more painful than the breach itself. Is your SRA current for 2026? If not, meet with our team of experts today to get compliant.

  • Facebook
  • Instagram
  • LinkedIn
  • YouTube
Abyde Logo

1.800.594.0883 | info@abyde.com

Automated HIPAA and OSHA Compliance

Our Reviews

From Our Blog
  • Don’t Get Caught Off Guard: HIPAA Audits are Back!
  • Don’t Be a Statistic: Why OSHA Compliance Matters in Healthcare
  • What Money Doesn’t Cover: The True Price of HIPAA Non-Compliance
  • HIPAA: It’s Not Just a Training – Your Guide to Continuous Compliance
Solutions
  • HIPAA for Covered Entities
  • OSHA for Healthcare
  • HIPAA for Business Associates
  • SRA for Covered Entities
  • Abyde Incident Response Program
  • Abyde Reseller Program
Resources
  • News
  • Events
  • Partners
  • HIPAA Badges
  • OSHA Badges
  • Learning Center
  • Compliance FAQs
Company
  • About Us
  • Who We Serve
  • Pricing
  • Contact Us
  • Newsletter
  • Jobs
  • COPYRIGHT © 2026 ABYDE
  • |

  • TERMS & CONDITIONS
  • |

  • PRIVACY POLICY
  • |

  • SECURITY MEASURES
  • |

  • E-SIGNATURE TERMS