Skip to content
  • About Us
    • Who We Serve
  • Solutions
    • HIPAA for Covered Entities
    • OSHA for Healthcare
    • HIPAA for Business Associates
    • SRA for Covered Entities
    • Abyde Incident Response Program
    • Abyde Reseller Program
  • Resources
  • News
  • Events
  • Partners
  • Contact Us
  • Login
    • HIPAA for Covered Entities
    • OSHA for Healthcare
    • HIPAA for Business Associates
    • SRA for Covered Entities
SIGN UP
BOOK A DEMO

Jacksonville, FL Psychiatric Treatment Facility Faces OSHA Fines After Failing to Protect Workers

July 27, 2023

In a recent investigation, the U.S. Department of Labor’s Occupational Safety and Health Administration (OSHA) discovered alarming safety lapses at a psychiatric health and substance disorder facility in Jacksonville, Florida. The facility, operating as River Point Behavioral Health, failed to implement necessary safety procedures, exposing its workers to serious risks and injuries. One incident involved a patient attacking a registered nurse, highlighting the urgent need for improved workplace safety measures.

Workplace Violence Plagues Healthcare Workers

The incident occurred in January 2023, when a registered nurse employed by UHS of Delaware Inc. and TBJ Behavioral Center LLC was working on reports in a staff-only workspace. Tragically, a patient gained unauthorized access to the area and physically assaulted the nurse, delivering blows to the face and head, resulting in a loss of consciousness and lacerations. This unfortunate incident highlights the growing concern about workplace violence faced by healthcare workers nationwide.

OSHA’s Findings and Consequences

Following the investigation, OSHA cited River Point Behavioral Health for a serious violation, holding them responsible for failing to provide a safe workplace free from recognized health and safety hazards. The agency proposed penalties amounting to $15,625. OSHA’s Area Office Director, Scott Tisdale, emphasized the importance of employers taking swift action to prevent such incidents, ensuring their employees’ physical well-being and peace of mind.

A Pattern of Neglect

This investigation is not an isolated incident for UHS of Delaware Inc. Since 2017, OSHA has looked into three other Florida facilities affiliated with the company due to similar complaints related to workplace violence. The pattern of neglect raises concerns about the company’s commitment to employee safety and the urgent need for comprehensive reforms.

Creating Safer Work Environments

Workplace violence is a pressing issue, particularly within the healthcare sector. Employers must take proactive steps to prevent and address such hazards to ensure the safety of their staff. Safety protocols, proper training, and secure workspaces are just a few measures that can significantly reduce the risks healthcare workers face on a daily basis.

UHS Inc.’s Role and Responsibility

River Point Behavioral Health is affiliated with UHS of Delaware Inc., which is part of UHS Inc., a prominent hospital and healthcare services system with a vast network of facilities in the U.S., Puerto Rico, and the U.K. As a major player in the healthcare industry, UHS Inc. must take the lead in advocating for improved workplace safety standards and ensuring the well-being of its employees. No organization is too big (or small) for OSHA compliance.

Compliance and Future Outlook

River Point Behavioral Health has 15 business days to respond to OSHA’s citations and penalties. The facility can choose to comply with the recommended changes, request an informal conference with OSHA, or contest the findings before the independent Occupational Safety and Health Review Commission. Regardless of the outcome, this investigation serves as a wake-up call for healthcare facilities nationwide to prioritize employee safety and work towards a violence-free workplace.

The recent OSHA investigation sheds light on the pressing issue of workplace violence in psychiatric facilities and healthcare settings. Ensuring employee safety must become a top priority for all industry stakeholders. By implementing comprehensive OSHA compliance software like Abyde and addressing hazards promptly, we can create a work environment where healthcare workers no longer fear for their lives and physical well-being. Together, we can build a safer and more compassionate healthcare industry for patients and those who care for them.

RECENT POSTS

  • Spencer Gifts HIPAA Fine
    Spencer Gifts HIPAA Settlement: Ransomware, Risk Analysis, and What Comes Next
  • OCR Ransomware Settlements
    OCR Ransomware Settlements: 4 Massive HIPAA Fines from April 2026 & How to Avoid Them
  • OSHA 2026 GHS Deadlines
    2026 OSHA HazCom Deadlines: How the GHS Update Impacts Your Practice
PrevPreviousSafeguarding Healthcare: A Lighthearted Look at Vital OSHA Regulations
NextSR-Hey, Have You Conducted a Security Risk Analysis?Next

Related posts

Spencer Gifts HIPAA Fine
Abyde News, Fines, HIPAA

Spencer Gifts HIPAA Settlement: Ransomware, Risk Analysis, and What Comes Next

June 19, 2026 Penelope Schweitzer No comments yet

June 19, 2026   Quick Guide:  The Office for Civil Rights issued a major fine towards Spencer Gifts benefits plan. This fine reinforces that all HIPAA-regulated entities must have a thorough compliance program.    The Stats You Need to Know 76%: The percentage of large healthcare breaches now caused by hacking/IT incidents. $450,000: Financial settlement of this enforcement. 10,023: The number of individuals were impacted in this breach.  264%: The increase in ransomware-related breaches reported to the OCR since 2018.   When you think about Spencer’s, you likely picture the staple mall store with pop culture novelty gifts, not the latest HIPAA settlement enforcement headline.  Spencer Gifts LLC Flexible Benefits and Welfare Benefit Plans, or their employee benefits plan, reached a settlement with the Office for Civil Rights for $450,000 and a 2 year Corrective Action Plan (CAP).  This fine is a reminder that Covered Entities include all parties that create and utilize patient data, including health care plans. While they might not see patients traditionally, they still are responsible for keeping Protected Health Information (PHI) secure.    What Happened?   In response to employee complaints regarding access to their employee benefits portal, Spencer Gifts Health Plan discovered their systems were infiltrated with ransomware in November 2021. Malicious actors encrypted over 10,000 individuals’ PHI and demanded a ransom. The exposed data included names, phone numbers, social security numbers, and more, putting employees at risk.  The breach was reported in January 2022. After years of investigation, it was settled that the plan failed to meet basic HIPAA Security Rule requirements proactively.    The Compliance Gaps A common misconception is that an organization faces a financial penalty due to a breach. While the breach serves as the catalyst for the investigation, the OCR is looking to see if an organization has a thorough compliance program in place and made a genuine effort to protect patient data.  For instance, the health plan did not complete a Security Risk Analysis (SRA). This required assessment identifies all technical, administrative, and physical safeguards (and vulnerabilities) across your organization. By completing this document, your organization can address concerns before they become an issue. There’s no way to know where risks are unless they are properly reviewed.  Additionally, the plan did not have sufficient policies and procedures, nor trained staff adequately. Without sufficient policies and training, staff are left without the tools to recognize and respond to HIPAA threats before they escalate. As a result, Spencer Gifts now faces $450,000 in penalties and two years of government monitoring to ensure those missing requirements are finally implemented. And that figure doesn’t account for the years of investigation, legal fees, breach notification costs, and operational disruption that preceded the settlement.   The Biggest Takeaway This case isn’t only a lesson for retail organizations’ health plans, but it’s a warning for every HIPAA-regulated entity. The OCR can and will investigate any organization exposed for failing to meet HIPAA requirements, including small medical practices To be prepared before a cyberattack occurs, make sure your organization has: A completed and current Security Risk Analysis. A trained workforce that knows how to handle PHI Accessible policies and procedures staff can actually reference. An up-to-date compliance program.  Ready to strengthen your compliance program? Schedule a free educational consultation with our team today.

OSHA 2026 GHS Deadlines
Abyde News, Legislation, OSHA

2026 OSHA HazCom Deadlines: How the GHS Update Impacts Your Practice

March 23, 2026 Penelope Schweitzer No comments yet

March 23, 2026   Quick Guide: 2026–2028 OSHA HazCom Deadlines (as of March 2026) May 19, 2026: Deadline for manufacturers to update labels for pure substances. Nov 20, 2026: Deadline for practices to update written HazCom programs and staff training for substances. May 19, 2028: Final deadline for practices to be fully compliant for all mixtures (disinfectants, resins, etc.). If you came here after hearing that a major OSHA deadline is coming up in May 2026, then you can exhale. You aren’t late (yet)… although if you are reading this closer to November, you can panic [a little]. The changes are actually not terribly complex for your practice, as we will explain in this blog, so you can be prepared.   What is GHS, and why does it exist? The Globally Harmonized System can be thought of as a standardized or universal language that is aligned with GHS Revision 7. Since chemical manufacturing occurs all over the globe, something made in one country might use different warning symbols and formats than something made here in the U.S., which can be confusing, if not problematic, for those who use them.  OSHA is updating its standards so that every chemical label and Safety Data Sheet (SDS) uses the same icons (called pictograms) and formatting worldwide, helping your team to easily identify what is what, no matter where the product came from.   Why are there so many deadlines? There are really two different audiences for the deadlines: manufacturers and consumers of the chemicals. There are also two waves of chemical classes with different priorities: Pure Substances and Mixtures. Wave 1 – Pure Substances (Deadline: Nov 20, 2026) This first wave covers “pure” chemicals, or products that have only one main ingredient. For many practices, this list tends to be short including (but not limited to) medical gas – like 100% Oxygen or Nitrous Oxide, bulk alcohol – like 99% Isopropyl Alcohol, etc. Wave 2 – Mixtures (Deadline: May 19, 2028) Most products are likely “mixtures” of several chemicals. Because these are more complex to re-label, OSHA has given everyone until 2028 to reach full compliance. This includes most surface disinfectants, cleaners, clinical materials, etc. What if we mix things ourselves? Most mixtures you do in-house are probably to dilute other “mixtures” (ie: secondary container labeling). But say, for instance, you still mix your own amalgam – you have a unique situation where you’re dealing with two different deadlines. Your mercury needs updated labels by Nov 2026, but the alloy you’re mixing with would fit the mixture deadline, as would the final product.   When will we see changes? You might have heard about a May 19, 2026, deadline. That is the deadline for the manufacturers to have their pure substance labels ready. Here is when you can expect to see the changes in your orders: May 2026 (Manufacturer Deadline) New labels for pure substances. Nov 2027 (Manufacturer Deadline) New labels for all mixtures.   Should I be doing anything now? Just be aware of the changes and try to notice them. You may already see some manufacturers have these changes live; others may happen by the deadline. The key is effective Safety Data Sheet (SDS) management. When a new version of an SDS arrives, simply swap it out in your library (whether that’s a physical binder or stored digitally). Replacing them as they come in is much easier than doing a mass update in November. If you haven’t received new sheets for your pure substances by this summer, you can reach out to your vendor to request the GHS-aligned version. The other change you’ll notice is products adding the GHS hazard pictograms where previously they had none or few. When you spot these, show them to your team during a morning meeting and explain what each icon means. It’s a simple way to keep staff informed and safe. Beyond that, start thinking about updates to your OSHA Hazard Communication training.   Need Help? We get it, you didn’t get into healthcare to become an OSHA expert… But we did. If you want to stay up to date on the deadlines and get the easy button covered for OSHA compliance, our platform and our compliance experts are here to help you do exactly that. If you’d like to learn more about Abyde and how we can help, check out our OSHA for Healthcare platform.

MMG Fusion HIPAA Settlement
Abyde News, Fines, HIPAA

15 Million Reasons to Review Your Business Associates: Lessons from the MMG Fusion Settlement

March 6, 2026 Penelope Schweitzer No comments yet

March 6, 2026 They say a mistake ignored is a disaster in the making. For one dental software provider, a 2020 breach became a 15-million-patient nightmare in 2026. MMG Fusion LLC, a dental marketing software business in Maryland, is in the crosshairs of the OCR and the subject of the latest HIPAA enforcement action. MMG agreed to a $10,000 settlement and a 3-year Corrective Action Plan (CAP).  The latest HIPAA settlement, and the 12th Enforcement Action in the Office for Civil Rights (OCR) Risk Analysis Initiative, highlighted the importance of completing a thorough Security Risk Analysis (SRA), proper Breach Notification, and choosing the right Business Associate (BA).  What Happened?  In December 2020, a malicious actor infiltrated MMG’s systems. Over 15 million patients’ Protected Health Information (PHI) was exposed in the cybercrime and leaked to the dark web.  Under the HIPAA Breach Notification Rule, a BA must notify affected Covered Entities (the dental practices) within 60 days of discovering a breach. However, the OCR didn’t learn about this 2020 incident until a complaint was filed in March 2023, more than two years later. The investigation uncovered a critical flaw: MMG Fusion lacked a compliant Security Risk Analysis (SRA). The SRA is a comprehensive review of an organization’s physical, technical, and administrative safeguards to protect PHI. A thorough SRA likely would have identified the very system vulnerabilities that the hackers exploited in 2020. Although the OCR factored in MMG’s “small business” status when determining the $10,000 fine, this amount does not account for the years the investigation took, the accumulated costs of legal counsel, stress, and reputational damage that occurred before the fine was made public. Additionally, MMG will also need to report to the OCR for 3 years in accordance with the CAP settlement.  Streamline Your Compliance This case highlights three non-negotiable pillars for every HIPAA-regulated entity: compliant HIPAA risk assessments, timely breach notification to the OCR and impacted parties, and choosing the right business partner to handle your sensitive information.  Managing vendors and staying on top of SRAs is overwhelming for a busy healthcare organization.  Modern software solutions automate the SRA process and generate compliant Business Associate Agreements (BAAs) for Covered Entities and BAs to use, ensuring both parties are held accountable.  Ready to learn more? Meet with an expert today!

  • Facebook
  • Instagram
  • LinkedIn
  • YouTube
Abyde Logo

1.800.594.0883 | info@abyde.com

Automated HIPAA and OSHA Compliance

Our Reviews

From Our Blog
  • Don’t Get Caught Off Guard: HIPAA Audits are Back!
  • Don’t Be a Statistic: Why OSHA Compliance Matters in Healthcare
  • What Money Doesn’t Cover: The True Price of HIPAA Non-Compliance
  • HIPAA: It’s Not Just a Training – Your Guide to Continuous Compliance
Solutions
  • HIPAA for Covered Entities
  • OSHA for Healthcare
  • HIPAA for Business Associates
  • SRA for Covered Entities
  • Abyde Incident Response Program
  • Abyde Reseller Program
Resources
  • News
  • Events
  • Partners
  • HIPAA Badges
  • OSHA Badges
  • Learning Center
  • Compliance FAQs
Company
  • About Us
  • Who We Serve
  • Pricing
  • Contact Us
  • Newsletter
  • Jobs
  • COPYRIGHT © 2026 ABYDE
  • |

  • TERMS & CONDITIONS
  • |

  • PRIVACY POLICY
  • |

  • SECURITY MEASURES
  • |

  • E-SIGNATURE TERMS