Skip to content
  • About Us
    • Who We Serve
  • Solutions
    • HIPAA for Covered Entities
    • OSHA for Healthcare
    • HIPAA for Business Associates
    • SRA for Covered Entities
    • Abyde Incident Response Program
    • Abyde Reseller Program
  • Resources
  • News
  • Events
  • Partners
  • Contact Us
  • Login
    • HIPAA for Covered Entities
    • OSHA for Healthcare
    • HIPAA for Business Associates
    • SRA for Covered Entities
SIGN UP
BOOK A DEMO

Fines

OCR Ransomware Settlements
Abyde News, Fines, HIPAA

OCR Ransomware Settlements: 4 Massive HIPAA Fines from April 2026 & How to Avoid Them

May 4, 2026 Penelope Schweitzer No comments yet

May 4, 2026   Quick Guide:  The Office for Civil Rights (OCR) just issued a massive wake-up call, announcing four simultaneous settlements totaling $1,165,000. The Stats You Need to Know 76%: The percentage of large healthcare breaches now caused by hacking/IT incidents. 427,000+: Total number of patients impacted across these four recent settlements. 264%: The increase in ransomware-related breaches reported to the OCR since 2018. The Office for Civil Rights (OCR) just announced a flurry of investigation settlements. At the root of the four that were announced: ransomware. Ransomware attacks continue to target healthcare facilities. As of last year, the OCR discovered that 76% of large breaches are due to hacking and IT shortcomings. Unfortunately, healthcare information is a goldmine for hackers, exposing sensitive data that can lead to identity theft, financial fraud, and compromised patient care. Breakdown & Lessons Learned Regional Women’s Health Group (Axia) The first settlement was regarding the Regional Women’s Health Group (Axia), an OBGYN network across five states. In this case, the organization submitted a breach report following a cyberattack that exposed over 37,000 patients. The settlement resulted in a $320,000 fine and a 2-year Corrective Action Plan (CAP). The Lesson: The OCR didn’t just fine them for being hacked; they reached a settlement because the healthcare organization failed to conduct a “thorough and accurate” Security Risk Analysis (SRA). If you don’t know where your vulnerabilities are, you can’t patch them. Unfortunately, hackers counted on this negligence and exploited it.  Assured Imaging This was the largest of the four fines, affecting a staggering 244,813 individuals. When a ransomware infection hit their servers, Assured Imaging, a medical imaging enterprise, reported a breach to the OCR. After a long investigation (the initial cyberattack occurred in 2020), and resulted in a $375,000 settlement and a 2-year CAP.  The Lesson: Beyond the initial ransomware attack, it was discovered that Assured had never completed an SRA. Additionally, the organization did not notify patients within 60 days of discovery of the breach. This is a direct violation of the Breach Notification Rule, which aims to allow patients to take control and mitigate risks as quickly as possible.  Consociate Health Consciate Health is the only Business Associate (BA) fine in the four. BAs continue to be under the OCR’s microscope, such as potentially needing to follow stricter requirements when handling patient data. Their breach started with a phishing attack that eventually led to the encryption of systems holding data for over 136,000 people. The BA discovered the ransomware six months after the initial phishing attack. Upon the OCR’s further investigation, the SRA was found to be insufficient. The organization paid a $225,000 settlement and entered into a 2-year CAP.  The Lesson: Human error (phishing) is the most common entry point for ransomware. Constant employee training is just as important as a strong firewall. Additionally, just because a BA doesn’t directly work with patients doesn’t mean it isn’t their responsibility to keep patient data secure.  SG Health Plan Even employee benefit plans are regulated under the Health Insurance Portability and Accountability Act (HIPAA). SG Health Plan, associated with a Connecticut energy provider, reported that the data of 9,316 members were exposed following a ransomware attack. It was discovered that the organization did not complete an extensive SRA. The benefit plan entered a settlement with the OCR for $245,000 and a 2-year CAP.  The Lesson: This settlement highlights that HIPAA applies to corporate health plans just as much as it does to traditional healthcare providers. Additionally, every organization that handles Protected Health Information (PHI) must complete an SRA.  The Bottom Line The OCR isn’t fining practices for ransomware attacks, but for being ill-prepared.  However, it is easier said than done to ensure your organization is secure in protecting patient data and complying with HIPAA.  Proactively implementing the HIPAA Security Rule is your opportunity to mitigate the impacts of a cyberattack. Waiting until the ransom note appears on your screen is a million-dollar mistake. Want to see what you might be missing?  Run a 5-Minute HIPAA Gap Assessment and protect your practice today! 

Abyde News, Fines, HIPAA

One Patient Request, Years of Fallout: The Concentra Right of Access Case

December 22, 2025 Penelope Schweitzer No comments yet

December 22, 2025 Well, the Office for Civil Rights (OCR) is back, folks!  After a historic government shutdown, the OCR has announced its first fine.  The recipient of the latest fine is Concentra, Inc., a Texas-based enterprise healthcare provider. While this health organization might have numerous locations, the root of this federal fine and years of legal battles stems from one patient complaint to the OCR.  With the 21st fine of the year, we’re taking it back to the basics: Patient Right of Access.  What Happened?  In February 2018, a patient requested a copy of their medical and billing records from Concentra’s Peoria, Arizona, location. While a Concentra employee forwarded the request to the billing office, the patient did not receive their medical records in a timely manner. The patient sent several requests throughout the year.  In October 2018, Concentra’s Business Associate issued an invoice to the patient for $82.57 for the requested medical records. This amount was disputed.  After months of back-and-forth with Concentra, in December 2018, the patient filed a complaint with the OCR regarding how the healthcare provider handled their record request. Finally, in March 2019, over a year after the initial request, Concentra’s Business Associate provided the health records to the patient for an adjusted rate of $6.50.  Providing the records was just the beginning for Concentra. In the summer of 2020, the OCR notified the healthcare provider that this case indicated noncompliance with the Privacy Rule and provided Concentra with the opportunity to submit mitigating evidence.  Then, in 2021, the OCR proposed to levy a $250,000 penalty. After several more years of legal battles, the OCR settled this case in 2025 with a $112,500 settlement.  Patient Right of Access 101 This lengthy chain of events highlights the importance of promptly and thoroughly addressing patient requests.  Detailed in the Privacy Rule, patients have the right to access their health records within 30 days from the initial request, known as the Right of Access. This timely access empowers patients to make informed decisions about their healthcare. This 30-day timeline applies on the federal level. Depending on the state, your practice may be required to comply with more stringent timelines, as seen in California.  The 30-day timeline is firm, and a practice can only be granted an extension once, for an additional 30 days. In addition to adhering to a 30-day timeline, the fees for copies of records must be reasonable and feasible.  The acceptable fee for providing copies of documents is limited to the cost of labor for copying, supplies, postage, and any provided summary. Alternatively, your practice can charge a flat fee of not more than $6.50 instead of calculating these specific costs.   Keeping Your Practice Compliant (And Your Patients Happy) While following the Right of Access might seem straightforward, it’s one of the most common HIPAA violations practices make. There have been 50+ HIPAA Right of Access enforcement actions levied by the OCR.  With the right compliance program, you can ensure that your staff is aware of all requirements when handling patient requests. Clear policies and engaging training help you respond correctly, on time, and with confidence. Ready to ensure your practice is HIPAA compliant? Schedule a consultation with one of our compliance experts today.

HIPAA Fines in Dentistry
Abyde News, Fines, HIPAA

The Bite of HIPAA:  True Stories of Dental HIPAA Fines

July 15, 2025 Penelope Schweitzer No comments yet

July 15, 2025 Running your dental practice comes with its unique set of challenges. You’re wearing multiple hats, and it’s a stressful fashion statement. While OSHA is always on your radar, just from the nature of dentistry, forgetting about HIPAA can be costly.  While you think your practice would never be in the hot seat, small dental practices, you’d be mistaken.  See how to avoid these common pitfalls in your dental practice, allowing you to continue running it effectively.    Time is of the Essence: Right of Access Under the HIPAA Privacy Rule, HIPAA not only defines how Protected Health Information (PHI) needs to be secured but also how it needs to be shared with authorized parties. Right of Access is a part of this rule. This rule requires healthcare providers to deliver requested patient records within 30 days of the patient’s request.  Gums Dental Care, a small Maryland dental practice, was fined for violating this HIPAA requirement. The patient initially requested their records in April 2019. The practice did not provide records until May 2022.  The patient alerted the Office for Civil Rights, which started a long, overwhelming journey for Gums Dental. The OCR intervened countless times, requiring the practice to provide the patient with their records.  The dental practice continued to refuse to provide the patient with records, leading to more legal battles, money, and time wasted.  The grand finale? Over three years from the date of the first request, and countless interventions from the OCR, the practice was fined $70,000.   Less is More As the saying goes, “If you can’t say anything nice, don’t say anything at all.” This rule applies to all forms of communication and also works to avoid HIPAA violations.  While social media brings people together, you must tread a fine line when handling PHI and posting online. One part of this is responding to patient reviews.  You cannot confirm or deny that a patient attended your practice, even if the patient is talking positively about their experience there. If you’d like to use someone’s story for marketing materials, like a before-and-after photo of their smile, ensure they sign a consent form.  If someone leaves a negative review, you cannot defend your practice by sharing information about the patient. For example, if a patient consistently posts bad reviews but fails to mention that they are always late, you should not call them out publicly online. Instead, address the issue privately and communicate with them securely. Dentists have been fined for social media violations. Dr. U. Phillip Igbinadolor, a dentist in North Carolina, lost his temper after a patient left a negative review on the practice’s Google page. After the dentist posted PHI in response, ridiculing the patient, the patient reported him to the OCR.  As a result, the OCR fined the practice $50,000, showing that the price of failing to simply “keep your words to yourself” can be extraordinarily steep.   Coming Clean is Key With cybercrimes in healthcare skyrocketing and large data breaches due to ransomware attacks increasing by 264%, having the proper safeguards in place is crucial.  While no practice can be completely immune from a breach, the right barriers in place can mitigate risk and minimize impact. However, if your practice is breached, you must notify the OCR and patients quickly.  Under the HIPAA Breach Notification Rule, patients must always be notified within 60 days, regardless of the size of the breach. If the breach affects fewer than 500, your practice must inform the OCR within 60 days after the calendar year in which the event occurred. If a breach affects more than 500, the OCR, and depending on the state, the Attorney General, must be notified within 60 days as well.  The Indiana Attorney General recently fined Westend Dental, a multi-location dental practice in Indiana, for its response to a ransomware attack.  While the breach occurred in October 2020, the practice did not alert the required parties until October 2022, two years after the initial attack. The Attorney General began investigating this attack after a patient complaint, and it was then discovered that the practice attempted to cover up a ransomware attack.  The investigation discovered that, in addition to violating the HIPAA Breach Notification Rule, Westend Dental had improper training, unprotected servers, no Security Risk Analysis (SRA), missing policies, and more.  The outcome? A $350,000 fine from the Attorney General, highlighting the importance of proactive compliance and properly notifying affected parties after a healthcare breach.    How to Protect Your Dental Practice While compliance for your dental practice might feel overwhelming, the right solutions can streamline your compliance program.  Smart software solutions can pinpoint vulnerabilities and provide actionable insights to avoid common pitfalls dental practices face. The right compliance software can also provide a comprehensive hub for everything HIPAA-related for your practice, including right of Access training, social media guidelines, and the SRA.  Meet with a compliance expert today to learn more about streamlining compliance for your dental practice. 

Deer Oaks HIPAA Fine
Abyde News, Fines, HIPAA

Double Trouble, Major Fine: How Two Breaches Cost Deer Oaks $225,000

July 9, 2025 Penelope Schweitzer No comments yet

July 9, 2025   Handling a HIPAA investigation is stressful enough. Add a ransomware attack in the mix? A HIPAA nightmare.  The Office for Civil Rights (OCR) announced its first fine under the latest Director, Paula M. Stannard—a behavioral health organization fined $225,000 and placed under a two-year Corrective Action Plan (CAP).  This fine culminated several violations, but at its core, it was the lack of a Security Risk Analysis (SRA). This latest enforcement highlights the OCR’s ongoing heightened enforcement and the importance of a thorough, proactive compliance program before issues occur.    What Happened?  The behavioral health provider, Deer Oaks, a Texas-based Covered Entity, was first investigated in May 2023 following a patient complaint.  It was discovered that following a pilot program for an online patient portal wasn’t properly coded, publicly disclosing 35 patients’ Protected Health Information (PHI). This PHI included sensitive discharge paperwork and medical assessments that were easily accessible online. Unfortunately, this was only the beginning of the investigation for Deer Oaks. The OCR expanded its investigation when the behavioral health provider faced a ransomware attack in August 2023.  A malicious actor used a compromised account and held over 170,000 patients’ information for ransom. While there is no confirmation if the provider paid the ransom, improper account security led to this massive breach.  With two major HIPAA breaches within three months, the OCR didn’t have to dig deep to find the common thread: the missing SRA. The SRA is a thorough assessment of potential vulnerabilities a practice might face. In this situation, an SRA could have identified the employee portal or account password management as a concern. This would allow the practice to address these issues proactively.  From the initial investigation triggered by a patient complaint in May 2023 to the ransomware breach in August, the OCR fined the practice nearly a quarter of a million dollars and mandated two years of government oversight. These costly few months served as a valuable lesson in proactive compliance.   Protecting Your Practice A lapse in compliance, no matter how short, can lead to serious consequences. That’s why proactive compliance is essential.  Need a wake-up call? Over $7 million in fines have been levied since the beginning of 2025. The OCR has heightened its enforcement, already eclipsing the number of penalties from last year.  As the OCR continues enforcing HIPAA legislation, a robust compliance program is vital for your practice’s success.  With the right solution, your practice can streamline HIPAA compliance and easily complete requirements, like the SRA, without disrupting your practice’s workflow.  Meet with a compliance expert today to learn more about streamlining HIPAA compliance for your practice. 

Small Practice HIPAA Fines
Abyde News, Fines, HIPAA

Small Practices, Big Fines: Understanding HIPAA Penalties

July 7, 2025 Penelope Schweitzer No comments yet

July 7, 2025   Did you know that over half of physicians work in small medical practices with 10 or fewer physicians?  You likely wear many hats when working in or even running your small practice, from taking care of patients to clerical work, and of course, HIPAA compliance.  Although other priorities may push HIPAA compliance to the side, being compliant is essential for the success of your practice.  It’s a common misconception that since a practice is small, the Office for Civil Rights (OCR) will not investigate it if an issue occurs.  The OCR has fined several small practices recently, with ramped-up enforcement, nearing $10 million within the year’s first half.  Here are some of the most recent fines imposed on small medical practices and how your practice can avoid them.   The SRA Superpower Comprehensive Neurology, PC, a small neurology practice in New York, was recently fined $25,000 after a ransomware attack exposed the practice’s insufficient protections for securing Protected Health Information (PHI). Specifically, the practice did not have a Security Risk Analysis (SRA).  The SRA is an annual assessment of your practice’s administrative, technical, and physical safeguards, reviewing potential vulnerabilities. When handled properly, the SRA allows you to mitigate risks before a situation occurs.  While commonly missed, the SRA is the foundation of a successful practice. To combat this, the OCR has recently enacted the Risk Analysis Initiative, which has brought increased scrutiny and led to nearly a million dollars in fines since its implementation late last year. Completing an SRA is paramount to protect your small medical practice from similar initiatives. The SRA is a crucial protective barrier, proactively preventing issues before they escalate into significant problems. For instance, if the practice completed an SRA, they could have seen any technological shortcomings that led to the severity of the ransomware attack.    Alert the Press!  Vision Upright MRI, a small California healthcare provider focused on medical imaging, was fined $5,000 in May.  In addition to missing an SRA following a breach, the small practice from California did not adequately inform patients. As part of the Breach Notification Rule, relevant parties, like impacted patients, the OCR, and, depending on the size of the breach, the media, and more, must all be notified following a breach. Patients can decide how to secure their information by being informed, and the practice should pay for credit monitoring.  With over 21,000 patients’ PHI compromised, the practice needed to notify several parties quickly. Regardless of the breach’s size, a practice must inform all affected patients within 60 days of discovery. However, given that this breach affected over 500 patients, the OCR, media, and some states (like California), the state attorney general also required notification within that time frame. Once you have mitigated the situation and understood the full scope, it’s time to alert all necessary parties. If the breach impacts fewer than 500 patients, while patients still need to be notified within 60 days, the practice must notify the OCR within 60 days of the calendar year in which it occurred.    Deliver Records Swiftly  Gums Dental Care LLC, a small dental practice in Maryland, was fined $70,000 after refusing to provide a patient’s medical records.  Under the HIPAA Privacy Rule, patients must receive their medical records within 30 days of request. This requirement, known as the Right of Access, is one of the most common violations.  In this situation, Gums Dental Care provided records three years after the initial request. To avoid similar penalties, ensure all staff are trained efficiently to provide patient records. Quickly addressing patient requests prioritizes their needs, secures your practice, and builds patient trust.   Simplifying Compliance for Your Small Practice While following the complexities of HIPAA might feel overwhelming, with the right solution, it doesn’t have to be.  Intelligent software can streamline compliance for your practice, alleviating the responsibility and freeing time to spend with patients.  Smart solutions also encompass HIPAA’s requirements, including the SRA, breach logs, and staff training.  Schedule a consultation today to learn more about simplifying compliance for your small practice. 

2023 OSHA Fines Increase
Fines, Legislation, OSHA

Inflation Strikes on Eggs and OSHA Fines

January 13, 2023 Gaurav Modi Comments Off on Inflation Strikes on Eggs and OSHA Fines

January 13, 2023 To keep up with inflation and the ever-changing cost-of-living adjustments, the U.S. Department of Labor announced changes to Occupational Safety and Health Administration (OSHA) civil penalty amounts today. As part of a Congressional act passed in 1990, the Federal Civil Penalties Inflation Adjustment Act, and amended by the Federal Civil Penalties Inflation Adjustment Act Improvements Act of 2015, the Department completes an annual review by January 15th to evaluate and adjust civil money penalty levels against inflation.  We can expect the new penalty amounts, shown below, to take effect on January 17, 2023. Currently, penalties for serious and other-than-serious violations are $14,502 per violation. With the recent update, we are seeing over a $1,000 increase to $15,625. Repeated violations aren’t getting a break either with an increase to $156,259 per violation from the previous $145,027.  Type of Violation Penalty SeriousOther-Than-SeriousPosting Requirements $15,625 per violation Failure to Abate $15,625 per day beyond the abatement date Willful or Repeated $156,259 per violation  Curious about state-specific updates? Per the U.S. Department of Labor, states that operate their own OSHA Plans are required to adopt maximum penalty levels that are at least as effective as Federal OSHA’s. State Plans are not required to impose monetary penalties on state and local government employers.  This new rule goes into effect on January 15, 2023. It will apply to any penalties assessed after January 15, 2023.  Before you go egging the next OSHA enforcement officer you come in contact with, remember that these annual updates are in place to remind you of the importance of maintaining a safe and healthful work environment.

Recent Posts

  • What OSF Healthcare’s Ransomware Fine Teaches Every Practice About SRAs
  • Spencer Gifts HIPAA Settlement: Ransomware, Risk Analysis, and What Comes Next
  • OCR Ransomware Settlements: 4 Massive HIPAA Fines from April 2026 & How to Avoid Them
  • 2026 OSHA HazCom Deadlines: How the GHS Update Impacts Your Practice
  • 15 Million Reasons to Review Your Business Associates: Lessons from the MMG Fusion Settlement

Recent Comments

No comments to show.

Archives

  • August 2026
  • June 2026
  • May 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • September 2019
  • October 2018
  • July 2018
  • May 2018
  • November 2017
  • April 2017

Categories

  • Abyde News
  • Audits
  • Best Practices
  • Business Associates
  • Cybersecurity
  • Fines
  • HIPAA
  • Legislation
  • OSHA
  • Partner News
  • Facebook
  • Instagram
  • LinkedIn
  • YouTube
Abyde Logo

1.800.594.0883 | info@abyde.com

Automated HIPAA and OSHA Compliance

Our Reviews

From Our Blog
  • Don’t Get Caught Off Guard: HIPAA Audits are Back!
  • Don’t Be a Statistic: Why OSHA Compliance Matters in Healthcare
  • What Money Doesn’t Cover: The True Price of HIPAA Non-Compliance
  • HIPAA: It’s Not Just a Training – Your Guide to Continuous Compliance
Solutions
  • HIPAA for Covered Entities
  • OSHA for Healthcare
  • HIPAA for Business Associates
  • SRA for Covered Entities
  • Abyde Incident Response Program
  • Abyde Reseller Program
Resources
  • News
  • Events
  • Partners
  • HIPAA Badges
  • OSHA Badges
  • Learning Center
  • Compliance FAQs
Company
  • About Us
  • Who We Serve
  • Pricing
  • Contact Us
  • Newsletter
  • Jobs
  • COPYRIGHT © 2026 ABYDE
  • |

  • TERMS & CONDITIONS
  • |

  • PRIVACY POLICY
  • |

  • SECURITY MEASURES
  • |

  • E-SIGNATURE TERMS