September 21, 2026 The HHS Office for Civil Rights (OCR) has announced its biggest HIPAA settlement of the year, reaching nearly a million dollars. Ambry, a genetic testing and clinical genomics provider based in Aliso Viejo, California is at the center of this enforcement. A settlement was reached over a 2020 phishing attack that exposed the Protected Health Information (PHI) of more than 225,000 individuals. This settlement is a clear reminder that even large organizations trip up on HIPAA requirements. What happened In January 2020, an employee email account at Ambry was compromised through a phishing attack. The breach potentially exposed a wide range of PHI, including names, addresses, dates of birth, Social Security Numbers, financial details, and more. Ambry reported the breach to OCR in March 2020, which kicked off the investigation. Where OCR found gaps OCR’s investigation identified several HIPAA Security Rule gaps, including: No accurate, thorough risk analysis of risks and vulnerabilities to ePHI No process for cutting off access to ePHI when an employee left or no longer needed access No unique user IDs for tracking who was accessing ePHI systems These are baseline HIPAA requirements that every Covered Entity and Business Associate is expected to have in place. The settlement terms Ambry paid $700,000 and agreed to a two-year corrective action plan, under which it must: Complete a thorough risk analysis of ePHI confidentiality, integrity, and availability Build and execute a risk management plan addressing what that analysis turns up Review and update Security Rule policies and procedures as needed Implement unique user identification across all ePHI systems Train the whole workforce on those updated policies The takeaway for practices When 90% of healthcare hacks start with a successful phishing attempt, it’s key your team is aware of the role they play to keep data safe. Every practice should ask; Do we know exactly where our ePHI lives and how it moves through our systems? Do we have a current, documented risk analysis? Would we catch it fast if a former employee’s access wasn’t revoked? Looking for the first step of addressing these gaps? Meet with one of our compliance experts to see where you currently stand.
Right of Access Enforcement Hits Eye Care: Inside the Azul Vision Settlement
September 1, 2026 The Office for Civil Rights (OCR) announced its 55th settlement under the HIPAA Right of Access Initiative, and this one is a good reminder that “we’ll get to it” is an easy shortcut to a massive financial penalty. What happened Azul Vision, Inc., a California optometry enterprise healthcare provider, took nearly two years to provide a patient her healthcare records failed to give a patient timely access to her health records. She requested her records in January 2023. She didn’t actually receive them until January 2025, or two years later, and only after OCR opened an investigation following her complaint in April 2023. The importance of Right of Access The HIPAA Privacy Rule’s Right of Access is straightforward: patients are entitled to their healthcare records within 30 days of a request, with one possible 30-day extension if needed. The cost Azul Vision agreed to a two-year, OCR-monitored corrective action plan and paid $50,000. The corrective action plan requires the practice to: Review and revise its written policies and procedures for Privacy Rule compliance. Regularly report to HHS a log of every PHI access request it receives, including when it came in and when it was resolved, Train all workforce members on right of access requirements and the practice’s own procedures. Practical takeaways Have a documented, assigned process for access requests: not an informal “someone will handle it” arrangement. Track every request against the 30-day (or extended 60-day) clock: If nothing is timestamping requests, nothing is catching the ones that slip. Train staff specifically on right of access: this is a distinct Privacy Rule obligation from general HIPAA awareness, and it’s clearly one OCR is actively enforcing. The bottom line A single records request that went unanswered turned into a $50,000 penalty, two years of federal monitoring, and a detrimental hit to the organization’s reputation. That’s a steep price for what really comes down to a missing process. If your team can’t answer “what happens the moment a patient asks for their records?” right now, that’s the gap to close before your practice ends up as OCR’s next enforcement case. Want a streamlined way to close your compliance gaps? Meet with an Abyde expert today!
What OSF Healthcare’s Ransomware Fine Teaches Every Practice About SRAs
August 5, 2026 The latest HIPAA fine is another clear reminder that ransomware attacks are, unfortunately, here to stay in the healthcare industry. A settlement involving the OSF Healthcare System was recently announced by the Office for Civil Rights (OCR). As an enterprise healthcare provider in the midwest, the organization serves 174 locations, including 16 hospitals – a prime target for a ransomware attack. So, what happened? In April 2021, OSF discovered that they joined the unlucky club of ransomware victims when a malicious actor deployed Nephilim, a ransomware strain made to target larger organizations. Once the ransomware infected OSF systems, the hacker demanded payment or patient Protected Health Information (PHI) would be leaked online. In this attack, sensitive information like financial account information, driver’s license numbers, medical record numbers, and more, were all exposed. Over 53,000 patient records were exposed in this attack. When ransomware attacks in healthcare have soared 278% in recent years, it’s more of a when then an if your organization doesn’t have the right safeguards in place. While the breach was discovered in April, OSF healthcare reported the breach to the OCR in October. The OCR took it from there, digging into what precautions (or lack thereof) let this happen. What did the OCR discover? If you’ve read any of our other fine breakdowns, you already know where this is going: another missing Security Risk Analysis (SRA). The SRA is a required document every HIPAA-regulated entity (ie: every practice and their Business Associates that handle patient information) needs to complete. The SRA is a thorough review of the physical, technical, and administrative safeguards in place to prevent PHI ending up in the wrong hands. While the OCR didn’t specify exactly how the ransomware got into OSF’s system, a technical safeguard vulnerability was very likely the entry point. A proactive SRA could have flagged that gap before it turned into a major breach. In addition to missing this required documentation, OSF also took too long to report the breach to the OCR and notify affected patients. This is a direct violation of the Breach Notification Rule, which requires organizations to notify patients within 60 days of a discovered breach. Moreover, since the breach impacted more than 500 patients, OSF was also required to report this breach to the OCR within 2 months as well. Time is of the essence in every component of a breach, from securing systems to ensuring affected parties are aware to protect themselves and an over five month delay was unacceptable in the eyes of the OCR. What was the result? OSF’s settlement tops the list as the largest fine of the year, coming in at $552,250, plus government monitoring for the next two years. It’s very important to note that this breach occurred in 2021, meaning that over five years were spent from the initial breach, to investigations, to the public press releases. Also, the average cost of a healthcare breach is over 7 million dollars – from implementing secure systems, notifying patients, legal fees, and more. The Takeaway While the settlement payment and Corrective Action Plan (CAP) are just the cherries on top, this experience was a tremendous cost of time, money, and resources, highlighting the importance of making sure everything is secure before a situation occurs. So, when was the last time you looked at your SRA? It’s time to seriously analyze your current compliance posture. Ransomware groups don’t check whether you’re a small dental office or a 16-hospital health system before they attack, they check whether the door was left open. Time and again, OCR’s findings come back to the same root cause: organizations can’t secure what they haven’t even identified as a problem. Looking to review your current compliance standings? Meet with our team of experts for a complimentary educational consultation.
Spencer Gifts HIPAA Settlement: Ransomware, Risk Analysis, and What Comes Next
June 19, 2026 Quick Guide: The Office for Civil Rights issued a major fine towards Spencer Gifts benefits plan. This fine reinforces that all HIPAA-regulated entities must have a thorough compliance program. The Stats You Need to Know 76%: The percentage of large healthcare breaches now caused by hacking/IT incidents. $450,000: Financial settlement of this enforcement. 10,023: The number of individuals were impacted in this breach. 264%: The increase in ransomware-related breaches reported to the OCR since 2018. When you think about Spencer’s, you likely picture the staple mall store with pop culture novelty gifts, not the latest HIPAA settlement enforcement headline. Spencer Gifts LLC Flexible Benefits and Welfare Benefit Plans, or their employee benefits plan, reached a settlement with the Office for Civil Rights for $450,000 and a 2 year Corrective Action Plan (CAP). This fine is a reminder that Covered Entities include all parties that create and utilize patient data, including health care plans. While they might not see patients traditionally, they still are responsible for keeping Protected Health Information (PHI) secure. What Happened? In response to employee complaints regarding access to their employee benefits portal, Spencer Gifts Health Plan discovered their systems were infiltrated with ransomware in November 2021. Malicious actors encrypted over 10,000 individuals’ PHI and demanded a ransom. The exposed data included names, phone numbers, social security numbers, and more, putting employees at risk. The breach was reported in January 2022. After years of investigation, it was settled that the plan failed to meet basic HIPAA Security Rule requirements proactively. The Compliance Gaps A common misconception is that an organization faces a financial penalty due to a breach. While the breach serves as the catalyst for the investigation, the OCR is looking to see if an organization has a thorough compliance program in place and made a genuine effort to protect patient data. For instance, the health plan did not complete a Security Risk Analysis (SRA). This required assessment identifies all technical, administrative, and physical safeguards (and vulnerabilities) across your organization. By completing this document, your organization can address concerns before they become an issue. There’s no way to know where risks are unless they are properly reviewed. Additionally, the plan did not have sufficient policies and procedures, nor trained staff adequately. Without sufficient policies and training, staff are left without the tools to recognize and respond to HIPAA threats before they escalate. As a result, Spencer Gifts now faces $450,000 in penalties and two years of government monitoring to ensure those missing requirements are finally implemented. And that figure doesn’t account for the years of investigation, legal fees, breach notification costs, and operational disruption that preceded the settlement. The Biggest Takeaway This case isn’t only a lesson for retail organizations’ health plans, but it’s a warning for every HIPAA-regulated entity. The OCR can and will investigate any organization exposed for failing to meet HIPAA requirements, including small medical practices To be prepared before a cyberattack occurs, make sure your organization has: A completed and current Security Risk Analysis. A trained workforce that knows how to handle PHI Accessible policies and procedures staff can actually reference. An up-to-date compliance program. Ready to strengthen your compliance program? Schedule a free educational consultation with our team today.
OCR Ransomware Settlements: 4 Massive HIPAA Fines from April 2026 & How to Avoid Them
May 4, 2026 Quick Guide: The Office for Civil Rights (OCR) just issued a massive wake-up call, announcing four simultaneous settlements totaling $1,165,000. The Stats You Need to Know 76%: The percentage of large healthcare breaches now caused by hacking/IT incidents. 427,000+: Total number of patients impacted across these four recent settlements. 264%: The increase in ransomware-related breaches reported to the OCR since 2018. The Office for Civil Rights (OCR) just announced a flurry of investigation settlements. At the root of the four that were announced: ransomware. Ransomware attacks continue to target healthcare facilities. As of last year, the OCR discovered that 76% of large breaches are due to hacking and IT shortcomings. Unfortunately, healthcare information is a goldmine for hackers, exposing sensitive data that can lead to identity theft, financial fraud, and compromised patient care. Breakdown & Lessons Learned Regional Women’s Health Group (Axia) The first settlement was regarding the Regional Women’s Health Group (Axia), an OBGYN network across five states. In this case, the organization submitted a breach report following a cyberattack that exposed over 37,000 patients. The settlement resulted in a $320,000 fine and a 2-year Corrective Action Plan (CAP). The Lesson: The OCR didn’t just fine them for being hacked; they reached a settlement because the healthcare organization failed to conduct a “thorough and accurate” Security Risk Analysis (SRA). If you don’t know where your vulnerabilities are, you can’t patch them. Unfortunately, hackers counted on this negligence and exploited it. Assured Imaging This was the largest of the four fines, affecting a staggering 244,813 individuals. When a ransomware infection hit their servers, Assured Imaging, a medical imaging enterprise, reported a breach to the OCR. After a long investigation (the initial cyberattack occurred in 2020), and resulted in a $375,000 settlement and a 2-year CAP. The Lesson: Beyond the initial ransomware attack, it was discovered that Assured had never completed an SRA. Additionally, the organization did not notify patients within 60 days of discovery of the breach. This is a direct violation of the Breach Notification Rule, which aims to allow patients to take control and mitigate risks as quickly as possible. Consociate Health Consciate Health is the only Business Associate (BA) fine in the four. BAs continue to be under the OCR’s microscope, such as potentially needing to follow stricter requirements when handling patient data. Their breach started with a phishing attack that eventually led to the encryption of systems holding data for over 136,000 people. The BA discovered the ransomware six months after the initial phishing attack. Upon the OCR’s further investigation, the SRA was found to be insufficient. The organization paid a $225,000 settlement and entered into a 2-year CAP. The Lesson: Human error (phishing) is the most common entry point for ransomware. Constant employee training is just as important as a strong firewall. Additionally, just because a BA doesn’t directly work with patients doesn’t mean it isn’t their responsibility to keep patient data secure. SG Health Plan Even employee benefit plans are regulated under the Health Insurance Portability and Accountability Act (HIPAA). SG Health Plan, associated with a Connecticut energy provider, reported that the data of 9,316 members were exposed following a ransomware attack. It was discovered that the organization did not complete an extensive SRA. The benefit plan entered a settlement with the OCR for $245,000 and a 2-year CAP. The Lesson: This settlement highlights that HIPAA applies to corporate health plans just as much as it does to traditional healthcare providers. Additionally, every organization that handles Protected Health Information (PHI) must complete an SRA. The Bottom Line The OCR isn’t fining practices for ransomware attacks, but for being ill-prepared. However, it is easier said than done to ensure your organization is secure in protecting patient data and complying with HIPAA. Proactively implementing the HIPAA Security Rule is your opportunity to mitigate the impacts of a cyberattack. Waiting until the ransom note appears on your screen is a million-dollar mistake. Want to see what you might be missing? Run a 5-Minute HIPAA Gap Assessment and protect your practice today!
2026 OSHA HazCom Deadlines: How the GHS Update Impacts Your Practice
March 23, 2026 Quick Guide: 2026–2028 OSHA HazCom Deadlines (as of March 2026) May 19, 2026: Deadline for manufacturers to update labels for pure substances. Nov 20, 2026: Deadline for practices to update written HazCom programs and staff training for substances. May 19, 2028: Final deadline for practices to be fully compliant for all mixtures (disinfectants, resins, etc.). If you came here after hearing that a major OSHA deadline is coming up in May 2026, then you can exhale. You aren’t late (yet)… although if you are reading this closer to November, you can panic [a little]. The changes are actually not terribly complex for your practice, as we will explain in this blog, so you can be prepared. What is GHS, and why does it exist? The Globally Harmonized System can be thought of as a standardized or universal language that is aligned with GHS Revision 7. Since chemical manufacturing occurs all over the globe, something made in one country might use different warning symbols and formats than something made here in the U.S., which can be confusing, if not problematic, for those who use them. OSHA is updating its standards so that every chemical label and Safety Data Sheet (SDS) uses the same icons (called pictograms) and formatting worldwide, helping your team to easily identify what is what, no matter where the product came from. Why are there so many deadlines? There are really two different audiences for the deadlines: manufacturers and consumers of the chemicals. There are also two waves of chemical classes with different priorities: Pure Substances and Mixtures. Wave 1 – Pure Substances (Deadline: Nov 20, 2026) This first wave covers “pure” chemicals, or products that have only one main ingredient. For many practices, this list tends to be short including (but not limited to) medical gas – like 100% Oxygen or Nitrous Oxide, bulk alcohol – like 99% Isopropyl Alcohol, etc. Wave 2 – Mixtures (Deadline: May 19, 2028) Most products are likely “mixtures” of several chemicals. Because these are more complex to re-label, OSHA has given everyone until 2028 to reach full compliance. This includes most surface disinfectants, cleaners, clinical materials, etc. What if we mix things ourselves? Most mixtures you do in-house are probably to dilute other “mixtures” (ie: secondary container labeling). But say, for instance, you still mix your own amalgam – you have a unique situation where you’re dealing with two different deadlines. Your mercury needs updated labels by Nov 2026, but the alloy you’re mixing with would fit the mixture deadline, as would the final product. When will we see changes? You might have heard about a May 19, 2026, deadline. That is the deadline for the manufacturers to have their pure substance labels ready. Here is when you can expect to see the changes in your orders: May 2026 (Manufacturer Deadline) New labels for pure substances. Nov 2027 (Manufacturer Deadline) New labels for all mixtures. Should I be doing anything now? Just be aware of the changes and try to notice them. You may already see some manufacturers have these changes live; others may happen by the deadline. The key is effective Safety Data Sheet (SDS) management. When a new version of an SDS arrives, simply swap it out in your library (whether that’s a physical binder or stored digitally). Replacing them as they come in is much easier than doing a mass update in November. If you haven’t received new sheets for your pure substances by this summer, you can reach out to your vendor to request the GHS-aligned version. The other change you’ll notice is products adding the GHS hazard pictograms where previously they had none or few. When you spot these, show them to your team during a morning meeting and explain what each icon means. It’s a simple way to keep staff informed and safe. Beyond that, start thinking about updates to your OSHA Hazard Communication training. Need Help? We get it, you didn’t get into healthcare to become an OSHA expert… But we did. If you want to stay up to date on the deadlines and get the easy button covered for OSHA compliance, our platform and our compliance experts are here to help you do exactly that. If you’d like to learn more about Abyde and how we can help, check out our OSHA for Healthcare platform.
15 Million Reasons to Review Your Business Associates: Lessons from the MMG Fusion Settlement
March 6, 2026 They say a mistake ignored is a disaster in the making. For one dental software provider, a 2020 breach became a 15-million-patient nightmare in 2026. MMG Fusion LLC, a dental marketing software business in Maryland, is in the crosshairs of the OCR and the subject of the latest HIPAA enforcement action. MMG agreed to a $10,000 settlement and a 3-year Corrective Action Plan (CAP). The latest HIPAA settlement, and the 12th Enforcement Action in the Office for Civil Rights (OCR) Risk Analysis Initiative, highlighted the importance of completing a thorough Security Risk Analysis (SRA), proper Breach Notification, and choosing the right Business Associate (BA). What Happened? In December 2020, a malicious actor infiltrated MMG’s systems. Over 15 million patients’ Protected Health Information (PHI) was exposed in the cybercrime and leaked to the dark web. Under the HIPAA Breach Notification Rule, a BA must notify affected Covered Entities (the dental practices) within 60 days of discovering a breach. However, the OCR didn’t learn about this 2020 incident until a complaint was filed in March 2023, more than two years later. The investigation uncovered a critical flaw: MMG Fusion lacked a compliant Security Risk Analysis (SRA). The SRA is a comprehensive review of an organization’s physical, technical, and administrative safeguards to protect PHI. A thorough SRA likely would have identified the very system vulnerabilities that the hackers exploited in 2020. Although the OCR factored in MMG’s “small business” status when determining the $10,000 fine, this amount does not account for the years the investigation took, the accumulated costs of legal counsel, stress, and reputational damage that occurred before the fine was made public. Additionally, MMG will also need to report to the OCR for 3 years in accordance with the CAP settlement. Streamline Your Compliance This case highlights three non-negotiable pillars for every HIPAA-regulated entity: compliant HIPAA risk assessments, timely breach notification to the OCR and impacted parties, and choosing the right business partner to handle your sensitive information. Managing vendors and staying on top of SRAs is overwhelming for a busy healthcare organization. Modern software solutions automate the SRA process and generate compliant Business Associate Agreements (BAAs) for Covered Entities and BAs to use, ensuring both parties are held accountable. Ready to learn more? Meet with an expert today!
2026 HIPAA Compliance Alert: $103,000 Settlement for Risk Analysis Failure
February 23, 2026 The Office for Civil Rights (OCR) is back with a massive settlement to start 2026. A rehab center in Illinois, Top of the World Ranch Treatment Center (TWRTC), recently agreed to a $103,000 and 2-year Corrective Action Plan (CAP) settlement following a security breach that exposed major security vulnerabilities. This settlement is also the 11th enforcement of the Risk Analysis Initiative. The Top of the World Ranch Treatment Center HIPAA settlement was announced just days after the OCR officially enacted the Part 2 changes to the Notice of Privacy Practices. As of Feb 16, all Covered Entities, regardless of scope of practice, must update their Notices of Privacy Practices (NPP) to include special provisions regarding the handling of Substance Use Disorder (SUD) Protected Health Information (PHI). What Happened? In March 2023, an employee’s email account was compromised in a phishing attack, exposing fewer than 2,000 records. In the world of healthcare data breaches, where numbers often reach the millions, this was a relatively small but still severe incident. However, the OCR’s enforcement was not based on the size of the breach, but on missing paperwork. This breach report initiated an investigation that led the OCR to find the SUD facility had failed to complete a compliant Security Risk Analysis (SRA). The SRA is the foundation of a HIPAA-compliant practice and an extensive assessment of the potential vulnerabilities your practice might face. The SRA reviews the administrative, physical, and technical safeguards your practice must have in place. Since TWRTC hadn’t completed this proactive assessment, they missed the specific vulnerabilities in their technical defenses that eventually allowed a phishing email to succeed. The Bottom Line The Top of the World Ranch Treatment Center HIPAA settlement proves that the OCR doesn’t punish based on how ‘big’ a mistake is, but for a lack of preparation. Breaches happen, but your team’s readiness and response are what determine whether you face an enforcement action. You might think your practice is too small to be a target, but this settlement shows that if you have a breach, no matter the size, the first thing the OCR will ask for is your SRA. If you don’t have it, the legal repercussions could be far more painful than the breach itself. Is your SRA current for 2026? If not, meet with our team of experts today to get compliant.
2026 HIPAA Deadline: How to Update Your Notice of Privacy Practices (NPP) for SUD Records (42 CFR Part 2)
February 16, 2026 The latest HIPAA change is the latest updates to the Notice of Privacy Practices (NPP). As of February 16, 2026, the newest version of the NPP must include further information about how Substance Use Disorder (SUD) Protected Health Information (PHI) is handled and secured. While this was initially ruled under the Biden administration in 2024, the updated content has seen significant changes, including the removal of proposed legislation that would treat reproductive healthcare PHI differently. However, while some states still have additional requirements for handling reproductive care PHI, those requirements were struck down at the federal level by a court ruling in 2025. Now that the deadline is here, it’s essential to understand what these changes actually mean for your practice. What’s Actually Changing in the Document? The Final Rule requires practices to update this document for patients (posted on the website and provided in-person) by February 16, 2026. Your practice must also review whether your state has additional legislation regarding reproductive healthcare PHI. Expanded Scope for SUD Information: SUD records must now be included in the NPP for all Covered Entities, regardless of whether the practice focuses specifically on SUD treatment. Standard Disclosure Language: The notice must explicitly state how the practice discloses SUD records for Treatment, Payment, and Healthcare Operations (TPO). Legal Proceeding Protections: The NPP must state that SUD records cannot be disclosed in legal proceedings without specific written patient consent or a formal court order. Single consent for TPO: The rule does allow patients to sign one consent for all future uses/disclosures of TPO. Previously, SUD records were discussed in a separate document for patients to review. Fundraising Opt-Outs: If your practice uses SUD records for fundraising communications, the NPP must clearly provide patients with the opportunity to opt out. For example, if a rehabilitation center is seeking to raise money for a new facility, it cannot reach out to former patients who have clearly opted out. Redisclosure Warning: The notice must highlight that once PHI (including SUD records) is shared with an outside party, it may be subject to redisclosure by the recipient. In other words, once it’s shared, it’s tough to control how it is shared again by third parties. Universal Accessibility: To remain compliant, practices must ensure the NPP is accessible to all patients, which includes providing translated copies. State-Specific Requirements: Depending on your state, additional protections for reproductive health PHI may still be in place. Where do I start? First, ensure your Notice of Privacy Practices (NPP) is already specific to your practice. Your final notice must be specific, include your office address, and provide clear contact information for your Compliance or Privacy Officer. To remain compliant, this notice must also be prominently displayed on your website so patients can easily access and understand their rights. Your NPP should now include a section that addresses these SUD records directly. The federal government provides model language similar to this: When applicable, we may use or disclose 42 CFR Part 2 substance use disorder records for treatment, payment, and health care operations as permitted by law. Part 2 records will not be used or disclosed in legal or administrative proceedings against you without your specific written consent or a court order. Your NPP should now include a section that mentions fundraising as well. The federal government provides model language similar to this: If we were to use or disclose substance use disorder records protected by 42 CFR Part 2 in connection with fundraising, you have the right to opt out of receiving fundraising communications in advance, before any such communications are sent. Simplify Compliance Updating your NPP can feel like just another complicated task on an already full plate. For practices where you’re wearing many hats, finding the resources for a legal deep-dive is tough. The simplest way to handle the February 16, 2026, deadline is to lean on experts. Abyde has already done the heavy lifting, automating the necessary HIPAA and SUD record updates so you can focus on what you do best: take care of patients. Reach out to our team of experts to learn more about HIPAA updates affecting your practice. Disclaimer: This post is for informational purposes only and does not constitute legal advice. Health care privacy laws are subject to frequent change and vary by state. Consult with a qualified health care attorney or compliance officer to ensure your Notice of Privacy Practices meets all current federal and state requirements.
HIPAA Basics You Can’t Skip (Even If You’ve ‘Always Done It This Way’)
January 15, 2026 As your practice shakes off the post-holiday haze, it’s time to go back to basics. Before picking up the pace, it’s worth slowing down to look at the foundations. While your practice might have routine procedures, it’s time to double-check if they’re even compliant. The Training Refresh Staff must complete HIPAA training when joining your practice, but that’s not all. HIPAA requires annual training and updates after policy changes or breaches, and whenever staff review is needed. Long story short, your practice needs a lot of training. When in doubt, provide staff training to ensure they are comfortable and confident in handling Protected Health Information (PHI). Titles Matter Even in a small practice, it’s required to assign a HIPAA Compliance Officer (HCO). We know that ‘wearing many hats’ is the reality of a small team, but designating a clear leader for compliance provides a vital anchor. It ensures your staff knows exactly who to turn to for guidance. If the OCR ever comes knocking, they require a single point of contact to streamline the investigation. Social Media Savviness We hate to break it to you, but your Gen Z receptionist could make your practice viral for all the wrong reasons. Social media can be beneficial for sharing your practice to a larger audience, but your staff needs to handle it very carefully. While it might be fun to partake in the latest TikTok trend, make sure that any PHI cannot be seen in the clips, and do not include a patient in any content unless there is explicit consent to do so. Having a media consent form is key in these situations. Keep it General Alongside social media, Google reviews can be a great way to show you’re listening, but HIPAA changes what you can say. Even if the review is favorable, you cannot identify whether the patient has been in your practice or not. Even if the review details a specific experience at your practice, it’s their choice to disclose this information, and your job, under HIPAA, is not to confirm it. For instance, a good public review would be: Thanks for the kind words! If you have additional feedback, please call us at xxx-xxx-xxxx. If you get a negative review, keep your response brief and offline. First, check for spam or rule violations and report if necessary. Otherwise, don’t clarify details or if they’re a patient. A good response: Thank you for your feedback. We’d like to learn more. Please contact us at xxx-xxx-xxxx. Practices can, and have been, fined for improper Google review responses, so your team must remain calm and neutral online. Lock it Down While it might feel easier for your practice to use a single, shared email to log in and access everything, it’s much safer (and wiser) for every team member to have their own login with role-based permissions. Individual accounts create accountability, keep information organized, and enable the implementation of role-based access. Not everyone in your practice needs access to the same information, and they shouldn’t have it. For example, your receptionist likely doesn’t need access to X-rays or clinical notes, but they do need access to scheduling software. When permissions align with the job, you reduce the risk of accidental exposure and keep sensitive data limited to those who genuinely need it. Individual logins make off-boarding easy. When someone leaves, remove their access immediately without disrupting the team or requiring a shared password change. This small shift greatly boosts compliance and protects patient information. Change Habits Today It’s easy to let compliance fall to the bottom of the to-do list when you’ve “always done it this way”. Thankfully, intelligent software can streamline these requirements for you. With the right platform, you can ensure training is handled correctly, that dynamic policies and procedures are properly formatted for your team, and that you have access to a team of compliance experts when navigating difficult compliance questions. Take the next step: schedule a compliance consultation with our team. We’ll show you exactly how to meet HIPAA requirements, simplify your processes, and protect your practice with confidence. Contact us today to get started.









