August 26, 2025
When scrolling through your inbox, letting your guard down is easy.
Maybe you click on that email that looks like it’s from your bank without hesitation, or are swayed by the unsolicited message for a random all-expenses-paid trip. Unfortunately, phishing emails are everywhere, and they target the healthcare industry due to the sensitive nature of Protected Health Information (PHI).
BST & Co., CPAs, LLP, known as BST, is a victim of phishing scams. The New York accounting and consulting firm, which works with practices, received the latest HIPAA enforcement, with a $175,000 fine and a two-year Corrective Action Plan or close monitoring by the Office for Civil Rights (OCR).
The OCR discovered, after the fallout of a phishing email, that the Business Associate (BA) had failed to complete a Security Risk Analysis (SRA). This is the 10th enforcement of the Risk Analysis Initiative since its introduction last year.
An SRA is a requirement for all HIPAA-regulated entities to assess all potential vulnerabilities of any physical, technical, or administrative safeguard in their organization. By identifying any concerns before a breach occurs, organizations are able to better safeguard PHI, keeping both their business and patients safe.
This fine reminds us that BAs are just as responsible for upholding HIPAA as traditional medical practices and that completing the SRA is paramount.
What Happened?
On December 4, 2019, malware entered BST’s network after a successful phishing attempt. From December 4 to December 7, 170,000 patients’ PHI was exposed.
The OCR began its investigation after BST reported the breach in February 2020. The OCR discovered that BST had not completed a thorough SRA.
With a thorough SRA, BST could have seen the vulnerabilities regarding emails, or even how they secured Covered Entities’ PHI, and either prevented this breach or minimized its impact.
Compliant Business Associates Keep Patients Safe
Even though BST wasn’t treating patients directly, as an accounting and consulting firm they still had access to a Covered Entity’s PHI. That’s a clear reminder of just how important it is to make sure your Business Associates (BAs) are fully compliant.
When your BA follows a comprehensive HIPAA compliance program, your practice gains peace of mind and a stronger, more secure partnership.
The right solution helps you stay ahead of your BA responsibilities, whether that’s generating and maintaining Business Associate Agreements, providing staff training with practical tips like email safety, or completing a Security Risk Analysis (SRA) to uncover hidden risks.
Connect with our team of compliance experts today to learn more.