Office for Civil Rights

HHS Announces Former DHS Official Lisa J. Pino as New OCR Director

by Jill McKeon

HHS has appointed Lisa J. Pino as director of the Office for Civil Rights (OCR). OCR oversees civil rights enforcements, HIPAA regulations, security, privacy, and breach notification rules. Most...

Houston Provider Delayed Notice of Ransomware Attack for Months

by Jill McKeon

Gastroenterology Consultants in Houston, Texas, began notifying over 161,000 patients of a January ransomware attack on August 6. The notification came as a surprise to many patients who were unaware...

OCR Settles 20th HIPAA Right of Access Case With Nebraska Hospital

by Jill McKeon

The HHS Office for Civil Rights (OCR) settled its twentieth case under the HIPAA Right of Access Initiative, marked by an $80,000 civil monetary penalty paid by Nebraska-based Children’s Hospital...

15 Years Later, Walgreens’ HIPAA Violation Case Raises Questions

by Jill McKeon

Following a 2006 HIPAA violation investigation by Indianapolis news station WTHR, CVS and Rite Aid reached settlements with HHS’ Office for Civil Rights (OCR) and paid a combined $3.25 million in...

OCR Settles With West Virginia-Based DELC for HIPAA Right of Access Failure

by Jessica Davis

The Department of Health and Human Services Office for Civil Rights announced it reached a settlement with West Virginia specialist Diabetes, Endocrinology & Lipidology Center (DELC) for $5,000, to...

OCR Settles with AEON Clinical for $25K Over Multiple HIPAA Failures

by Jessica Davis

Peachstate Health Management, doing business as AEON Clinical Laboratories, has settled with the Department of Health and Human Services Office for Civil Rights for $25,000 and agreed to a...

HHS’ Proposed HIPAA Right of Access Changes: CHIME, ABHW Weigh in

by Jessica Davis

CHIME and the Association for Behavioral Health and Wellness sent letters to the Department of Health and Human Services, in response to proposed changes to HIPAA. Among a range of concerns are...

OCR Settles With NJ Specialist for Over HIPAA Right of Access Failure

by Jessica Davis

The Department of Health and Human Services Office for Civil Rights announced it reached a settlement with Village Plastic Surgery (VPS) to resolve potential violations of the HIPAA right of access...

Arbour Hospital Pays OCR $65K Over HIPAA Right of Access Violation

by Jessica Davis

The Department of Health and Human Services announced it reached a $65,000 settlement with Massachusetts-based Arbour Hospital, which resolved potential violations of the HIPAA right of access...

HHS Extends Comment Period for HIPAA Privacy Rule Changes

by Jessica Davis

The Department of Health and Human Services Office for Civil Rights announced it has extended the comment period for proposed changes to the HIPAA Privacy Rule. Proposed in December 2020, the changes...

$70K OCR Penalty for Sharp Health Over HIPAA Right of Access Failures

by Jessica Davis

California-based Sharp HealthCare, doing business as Sharp Rees-Stealy Medical Centers (SRMC), has agreed to a corrective action plan and to pay the Office for Civil Rights a $70,000 civil monetary...

Renown Health Pays OCR $75K for HIPAA Right of Access Failure

by Jessica Davis

The Office for Civil Rights reached a $75,000 civil monetary penalty and corrective action plan with Nevada-based Renown Health, to settle a potential violation of the HIPAA right of access...

OCR Lifts HIPAA Penalties for Use of COVID-19 Vaccine Scheduling Apps

by Jessica Davis

The Office for Civil Rights announced another enforcement discretion amid the pandemic, lifting penalties for potential HIPAA violations related to the good faith use of online or web-based scheduling...

Insurer Pays $5.1M OCR Penalty for Data Breach Involving 9.3M Patients

by Jessica Davis

New York-based Excellus Health Plan, doing business as Excellus BlueCross BlueShield and Univera Healthcare, agreed to a $5.1 million civil monetary penalty and a corrective action plan with the...

Judge Vacates $4.3M OCR Penalty Against MD Anderson Over Data Loss

by Jessica Davis

The US Court of Appeals for the Fifth Circuit has vacated the $4.3 million civil monetary penalty against the University of Texas MD Anderson Cancer Center after two years and several lost appeals. The...

Banner Health to Pay OCR $200K for HIPAA Right of Access Failures

by Jessica Davis

The Department of Health and Human Services Office for Civil Rights reached a $200,000 civil monetary penalty and a corrective action plan with Banner Health, to resolve potential violations of the...

OCR Guide on HIPAA-Compliant PHI Disclosures Via HIEs, Amid COVID-19

by Jessica Davis

The Office for Civil Rights recently released guidance for covered entities and business associates on HIPAA-permitted disclosures of protected health information through the use of health information...

Elite Primary Care Pays OCR $36K for HIPAA Right of Access Violation

by Jessica Davis

Elite Primary Care in Georgia has agreed to a $36,000 settlement with the Office for Civil Rights to resolve a potential violation of the HIPAA Privacy Rule's right of access...

OCR: Healthcare HIPAA Compliance Report Finds PHI Security Failures

by Jessica Davis

The Department of Health and Human Services Office for Civil Rights released an audit report on HIPAA compliance in the sector from 2016 to 2017 based on reviews of selected healthcare covered entities...

OCR Warns of Global Supply-Chain Cyberattacks Via SolarWinds Orion

by Jessica Davis

The Office for Civil Rights urges all healthcare organizations to review a Department of Homeland Security alert, warning of ongoing global supply-chain cyberattacks. Nation-state actors trojanized...