Skip to content
  • About Us
    • Who We Serve
  • Solutions
    • HIPAA for Covered Entities
    • OSHA for Healthcare
    • HIPAA for Business Associates
    • SRA for Covered Entities
    • Abyde Incident Response Program
    • Abyde Reseller Program
  • Resources
  • News
  • Events
  • Partners
  • Contact Us
  • Login
    • HIPAA for Covered Entities
    • OSHA for Healthcare
    • HIPAA for Business Associates
    • SRA for Covered Entities
SIGN UP
BOOK A DEMO

Staten Island Health Center Hit with $195K Fine for Silencing COVID Safety Whistleblower

January 31, 2024

Hi regulation rockstars! There have been some major new updates in OSHA fines. A Staten Island health center recently learned a $195,000 lesson on the importance of whistleblower protection during a global pandemic.

What Happened:

A Staten Island health center, Community Health Center of Richmond (CHCR), has been ordered to pay $195,000 to a former employee they illegally fired for raising concerns about an in-person staff meeting during the early days of the COVID-19 pandemic. Ouch.

The Whistleblower:

This brave employee, concerned about the health risks of an in-person meeting in March 2020, requested a teleconference instead. They even went ahead and changed the meeting format themselves. Talk about taking initiative!

Retaliation Bites Back:

Unfortunately, CHCR CEO Henry Thompson wasn’t having it. He insisted on the in-person meeting, putting the employee in a tough spot. Faced with the choice between their health and their job, the employee ultimately chose not to attend. But instead of understanding their concerns, CHCR suspended them for “insubordination” and then fired them shortly after. Yikes.

OSHA Steps In:

The employee, rightfully upset, filed a whistleblower complaint with OSHA. And guess what? OSHA investigated and found CHCR in violation of whistleblower protection laws. Big win for employee rights!

The Payout:

As part of a settlement, CHCR and Thompson are shelling out $195,000 to the employee, on top of other measures like:

  • Expunging the employee’s termination and suspension records
  • Providing a neutral job reference
  • Conducting employee training on safety concerns and whistleblower rights
  • Posting a notice promising not to retaliate against employees who raise safety concerns

The Takeaway:

This case sends a clear message: Employers can’t silence employees who raise safety concerns, especially during a pandemic.

Here’s what this means for you:

  • If you see something, say something. You have the right to raise safety concerns without fear of retaliation.
  • Know your rights. OSHA protects whistleblowers in various industries.
  • Don’t be afraid to speak up. This case shows that standing up for your safety and the safety of others can make a difference.

Remember, your health and safety matter. Don’t let employers bully you into silence. If you have concerns, speak up and know that you have rights. To learn more about your rights in the workplace, email info@abyde.com and schedule an educational consultation here. 

 

RECENT POSTS

  • OSF Healthcare HIPAA Settlement
    What OSF Healthcare's Ransomware Fine Teaches Every Practice About SRAs
  • Spencer Gifts HIPAA Fine
    Spencer Gifts HIPAA Settlement: Ransomware, Risk Analysis, and What Comes Next
  • OCR Ransomware Settlements
    OCR Ransomware Settlements: 4 Massive HIPAA Fines from April 2026 & How to Avoid Them
PrevPreviousThe Increase in HIPAA and OSHA Fines in 2024
NextBuilding a Culture of Compliance: How to Get Your Employees Onboard Across Multiple LocationsNext

Related posts

OSF Healthcare HIPAA Settlement
Abyde News, Fines, HIPAA

What OSF Healthcare’s Ransomware Fine Teaches Every Practice About SRAs

August 5, 2026 Penelope Schweitzer No comments yet

August 5, 2026 The latest HIPAA fine is another clear reminder that ransomware attacks are, unfortunately, here to stay in the healthcare industry. A settlement involving the OSF Healthcare System was recently announced by the Office for Civil Rights (OCR). As an enterprise healthcare provider in the midwest, the organization serves 174 locations, including 16 hospitals – a prime target for a ransomware attack.    So, what happened?  In April 2021, OSF discovered that they joined the unlucky club of ransomware victims when a malicious actor deployed Nephilim, a ransomware strain made to target larger organizations. Once the ransomware infected OSF systems, the hacker demanded payment or patient Protected Health Information (PHI) would be leaked online. In this attack, sensitive information like financial account information, driver’s license numbers, medical record numbers, and more, were all exposed. Over 53,000 patient records were exposed in this attack.  When ransomware attacks in healthcare have soared 278% in recent years, it’s more of a when then an if your organization doesn’t have the right safeguards in place.  While the breach was discovered in April, OSF healthcare reported the breach to the OCR in October. The OCR took it from there, digging into what precautions (or lack thereof) let this happen.  What did the OCR discover? If you’ve read any of our other fine breakdowns, you already know where this is going: another missing Security Risk Analysis (SRA).  The SRA is a required document every HIPAA-regulated entity (ie: every practice and their Business Associates that handle patient information) needs to complete. The SRA is a thorough review of the physical, technical, and administrative safeguards in place to prevent PHI ending up in the wrong hands. While the OCR didn’t specify exactly how the ransomware got into OSF’s system, a technical safeguard vulnerability was very likely the entry point. A proactive SRA could have flagged that gap before it turned into a major breach. In addition to missing this required documentation, OSF also took too long to report the breach to the OCR and notify affected patients. This is a direct violation of the Breach Notification Rule, which requires organizations to notify patients within 60 days of a discovered breach. Moreover, since the breach impacted more than 500 patients, OSF was also required to report this breach to the OCR within 2 months as well. Time is of the essence in every component of a breach, from securing systems to ensuring affected parties are aware to protect themselves and an over five month delay was unacceptable in the eyes of the OCR.    What was the result?  OSF’s settlement tops the list as the largest fine of the year, coming in at $552,250, plus government monitoring for the next two years.  It’s very important to note that this breach occurred in 2021, meaning that over five years were spent from the initial breach, to investigations, to the public press releases. Also, the average cost of a healthcare breach is over 7 million dollars –  from implementing secure systems, notifying patients, legal fees, and more. The Takeaway While the settlement payment and Corrective Action Plan (CAP) are just the cherries on top, this experience was a tremendous cost of time, money, and resources, highlighting the importance of making sure everything is secure before a situation occurs.  So, when was the last time you looked at your SRA? It’s time to seriously analyze your current compliance posture. Ransomware groups don’t check whether you’re a small dental office or a 16-hospital health system before they attack, they check whether the door was left open. Time and again, OCR’s findings come back to the same root cause: organizations can’t secure what they haven’t even identified as a problem. Looking to review your current compliance standings? Meet with our team of experts for a complimentary educational consultation. 

Spencer Gifts HIPAA Fine
Abyde News, Fines, HIPAA

Spencer Gifts HIPAA Settlement: Ransomware, Risk Analysis, and What Comes Next

June 19, 2026 Penelope Schweitzer No comments yet

June 19, 2026   Quick Guide:  The Office for Civil Rights issued a major fine towards Spencer Gifts benefits plan. This fine reinforces that all HIPAA-regulated entities must have a thorough compliance program.    The Stats You Need to Know 76%: The percentage of large healthcare breaches now caused by hacking/IT incidents. $450,000: Financial settlement of this enforcement. 10,023: The number of individuals were impacted in this breach.  264%: The increase in ransomware-related breaches reported to the OCR since 2018.   When you think about Spencer’s, you likely picture the staple mall store with pop culture novelty gifts, not the latest HIPAA settlement enforcement headline.  Spencer Gifts LLC Flexible Benefits and Welfare Benefit Plans, or their employee benefits plan, reached a settlement with the Office for Civil Rights for $450,000 and a 2 year Corrective Action Plan (CAP).  This fine is a reminder that Covered Entities include all parties that create and utilize patient data, including health care plans. While they might not see patients traditionally, they still are responsible for keeping Protected Health Information (PHI) secure.    What Happened?   In response to employee complaints regarding access to their employee benefits portal, Spencer Gifts Health Plan discovered their systems were infiltrated with ransomware in November 2021. Malicious actors encrypted over 10,000 individuals’ PHI and demanded a ransom. The exposed data included names, phone numbers, social security numbers, and more, putting employees at risk.  The breach was reported in January 2022. After years of investigation, it was settled that the plan failed to meet basic HIPAA Security Rule requirements proactively.    The Compliance Gaps A common misconception is that an organization faces a financial penalty due to a breach. While the breach serves as the catalyst for the investigation, the OCR is looking to see if an organization has a thorough compliance program in place and made a genuine effort to protect patient data.  For instance, the health plan did not complete a Security Risk Analysis (SRA). This required assessment identifies all technical, administrative, and physical safeguards (and vulnerabilities) across your organization. By completing this document, your organization can address concerns before they become an issue. There’s no way to know where risks are unless they are properly reviewed.  Additionally, the plan did not have sufficient policies and procedures, nor trained staff adequately. Without sufficient policies and training, staff are left without the tools to recognize and respond to HIPAA threats before they escalate. As a result, Spencer Gifts now faces $450,000 in penalties and two years of government monitoring to ensure those missing requirements are finally implemented. And that figure doesn’t account for the years of investigation, legal fees, breach notification costs, and operational disruption that preceded the settlement.   The Biggest Takeaway This case isn’t only a lesson for retail organizations’ health plans, but it’s a warning for every HIPAA-regulated entity. The OCR can and will investigate any organization exposed for failing to meet HIPAA requirements, including small medical practices To be prepared before a cyberattack occurs, make sure your organization has: A completed and current Security Risk Analysis. A trained workforce that knows how to handle PHI Accessible policies and procedures staff can actually reference. An up-to-date compliance program.  Ready to strengthen your compliance program? Schedule a free educational consultation with our team today.

OSHA 2026 GHS Deadlines
Abyde News, Legislation, OSHA

2026 OSHA HazCom Deadlines: How the GHS Update Impacts Your Practice

March 23, 2026 Penelope Schweitzer No comments yet

March 23, 2026   Quick Guide: 2026–2028 OSHA HazCom Deadlines (as of March 2026) May 19, 2026: Deadline for manufacturers to update labels for pure substances. Nov 20, 2026: Deadline for practices to update written HazCom programs and staff training for substances. May 19, 2028: Final deadline for practices to be fully compliant for all mixtures (disinfectants, resins, etc.). If you came here after hearing that a major OSHA deadline is coming up in May 2026, then you can exhale. You aren’t late (yet)… although if you are reading this closer to November, you can panic [a little]. The changes are actually not terribly complex for your practice, as we will explain in this blog, so you can be prepared.   What is GHS, and why does it exist? The Globally Harmonized System can be thought of as a standardized or universal language that is aligned with GHS Revision 7. Since chemical manufacturing occurs all over the globe, something made in one country might use different warning symbols and formats than something made here in the U.S., which can be confusing, if not problematic, for those who use them.  OSHA is updating its standards so that every chemical label and Safety Data Sheet (SDS) uses the same icons (called pictograms) and formatting worldwide, helping your team to easily identify what is what, no matter where the product came from.   Why are there so many deadlines? There are really two different audiences for the deadlines: manufacturers and consumers of the chemicals. There are also two waves of chemical classes with different priorities: Pure Substances and Mixtures. Wave 1 – Pure Substances (Deadline: Nov 20, 2026) This first wave covers “pure” chemicals, or products that have only one main ingredient. For many practices, this list tends to be short including (but not limited to) medical gas – like 100% Oxygen or Nitrous Oxide, bulk alcohol – like 99% Isopropyl Alcohol, etc. Wave 2 – Mixtures (Deadline: May 19, 2028) Most products are likely “mixtures” of several chemicals. Because these are more complex to re-label, OSHA has given everyone until 2028 to reach full compliance. This includes most surface disinfectants, cleaners, clinical materials, etc. What if we mix things ourselves? Most mixtures you do in-house are probably to dilute other “mixtures” (ie: secondary container labeling). But say, for instance, you still mix your own amalgam – you have a unique situation where you’re dealing with two different deadlines. Your mercury needs updated labels by Nov 2026, but the alloy you’re mixing with would fit the mixture deadline, as would the final product.   When will we see changes? You might have heard about a May 19, 2026, deadline. That is the deadline for the manufacturers to have their pure substance labels ready. Here is when you can expect to see the changes in your orders: May 2026 (Manufacturer Deadline) New labels for pure substances. Nov 2027 (Manufacturer Deadline) New labels for all mixtures.   Should I be doing anything now? Just be aware of the changes and try to notice them. You may already see some manufacturers have these changes live; others may happen by the deadline. The key is effective Safety Data Sheet (SDS) management. When a new version of an SDS arrives, simply swap it out in your library (whether that’s a physical binder or stored digitally). Replacing them as they come in is much easier than doing a mass update in November. If you haven’t received new sheets for your pure substances by this summer, you can reach out to your vendor to request the GHS-aligned version. The other change you’ll notice is products adding the GHS hazard pictograms where previously they had none or few. When you spot these, show them to your team during a morning meeting and explain what each icon means. It’s a simple way to keep staff informed and safe. Beyond that, start thinking about updates to your OSHA Hazard Communication training.   Need Help? We get it, you didn’t get into healthcare to become an OSHA expert… But we did. If you want to stay up to date on the deadlines and get the easy button covered for OSHA compliance, our platform and our compliance experts are here to help you do exactly that. If you’d like to learn more about Abyde and how we can help, check out our OSHA for Healthcare platform.

  • Facebook
  • Instagram
  • LinkedIn
  • YouTube
Abyde Logo

1.800.594.0883 | info@abyde.com

Automated HIPAA and OSHA Compliance

Our Reviews

From Our Blog
  • Don’t Get Caught Off Guard: HIPAA Audits are Back!
  • Don’t Be a Statistic: Why OSHA Compliance Matters in Healthcare
  • What Money Doesn’t Cover: The True Price of HIPAA Non-Compliance
  • HIPAA: It’s Not Just a Training – Your Guide to Continuous Compliance
Solutions
  • HIPAA for Covered Entities
  • OSHA for Healthcare
  • HIPAA for Business Associates
  • SRA for Covered Entities
  • Abyde Incident Response Program
  • Abyde Reseller Program
Resources
  • News
  • Events
  • Partners
  • HIPAA Badges
  • OSHA Badges
  • Learning Center
  • Compliance FAQs
Company
  • About Us
  • Who We Serve
  • Pricing
  • Contact Us
  • Newsletter
  • Jobs
  • COPYRIGHT © 2026 ABYDE
  • |

  • TERMS & CONDITIONS
  • |

  • PRIVACY POLICY
  • |

  • SECURITY MEASURES
  • |

  • E-SIGNATURE TERMS