Cal/OSHA Seeks Comment Workplace Violence Prevention Regulation Discussion Draft
Cal/OSHA is working on an update to the 2023 legislation that introduced a new requirement for employers in California to develop and implement a workplace violence prevention plan. Senate Bill 553, Workplace Violence Prevention in General Industry, was signed into law on September 30, 2023, and took effect on July 1, 2024. The legislation requires employers to develop, implement, and maintain a Workplace Violence Prevention Plan, the main components of which are: Prohibiting employee retaliation Accepting and responding to reports of workplace violence Providing employee workplace violence training and communication Emergency response procedures Conducting workplace violence hazard assessments Maintaining a Violent Incident Log The legislation was introduced in response to an increase in workplace violence, which across the United States, affects almost 2 million workers each year. In 2021, in California alone, there were 57 employee deaths from workplace violence. A summary of the current requirements has been published in a Cal/OSHA fact sheet. The legislation required Cal/OSHA...
House/Senate Bills Seek to Expand OSH Act to Cover Public Sector Workers
Senator Ed Markey (D-MA), for himself and on behalf of Sens. Chuck Schumer (D-NY), Bernie Sanders (I-VT), Ben Ray Luján (D-NM), Ron Wyden (D-OR), Chris Van Hollen (D-MD), Alex Padilla (D-CA), Richard Blumenthal (D-CT), Tammy Baldwin (D-WI), and Adam Schiff (D-CA) has recently introduced the Public Service Worker Protection Act, which seeks to expand the Occupational Safety and Health (OSH) Act to extend protections to public employees at the federal, state, and local levels. The OSH Act was introduced in 1970 and requires employers to maintain safe and healthful working conditions by requiring employees to be provided with a working environment free from recognized hazards that are likely to cause serious injury or death. Under the OSH Act, employers must comply with occupational safety and health standards promulgated under the OSH Act. The OSH Act also established the Occupational Safety and Health Administration (OSHA) within the U.S. Department of Labor to enforce OSH Act compliance. The OSH Act applies to most private sector employers and employees in the United States, but...
What is the Maximum Penalty for Violating HIPAA?
The maximum penalty for violating HIPAA is currently $71,162 (June 2025) for a violation that is attributable to willful neglect and that, despite being alerted to the violation by HHS’ Office for Civil Rights, is not corrected within 30 days. However, this figure represents the maximum penalty per violation type. It is often the case that data breaches are attributable to more than one HIPAA violation When Congress passed HIPAA in 1996, it set the maximum penalty for violating HIPAA at $100 per violation with an annual cap of $25,000. These limits were applied when the Department of Health & Human Services (HHS) published the Enforcement Rule in 2006 and they stayed in force until the publication of the Final Omnibus Rule in 2013. Among other changes to HIPAA, the Final Omnibus Rule introduced amendments to the Enforcement Rule attributable to passage of the HITECH Act in 2009. The HITECH Act mandated a four tier penalty structure for HIPAA violations and new minimum and maximum penalties for violating HIPAA. The four tiers were based on the level of culpability...
U.S. Dermatology Partners Announce June 2024 Cyberattack & Data Breach
Data breaches have recently been announced by U.S. Dermatology Partners in Texas, the Smith Institute for Urology in New York, Shore Medical Center in New Jersey, Connections for Kids in Maine, and the Missouri Department of Conservation. U.S. Dermatology Partners, Texas U.S. Dermatology Partners (USDP), a network of more than 100 dermatology practices in Arizona, Colorado, Kansas, Maryland, Missouri, Oklahoma, Texas, and Virginia, has recently announced a June 2024 cyberattack and data breach. USDP experienced network disruption on June 19, 2024, indicative of a cyberattack. Assisted by third-party digital forensics experts, USDP confirmed that there had been unauthorized access to its network on June 19, 2024, and files were exfiltrated to “an external destination”. A comprehensive review of those files was completed on April 2, 2025, when it was confirmed that the stolen data included names, dates of birth, medical record numbers, health insurance information, and other information related to the dermatology services received at one of its managed practices. A...
Serviceaide Facing Multiple Class Action Lawsuits Over 483K-Record Data Breach
A California company that provides an agentic AI-powered software solution for streamlining healthcare operations and improving operational efficiency has recently disclosed a major data breach involving the personal and protected health information of almost half a million patients of Catholic Health in Buffalo, New York. The HIPAA Journal reported on the breach on May 19, 2025, the same day six class action lawsuits were filed in federal court in California over the data breach. More lawsuits are expected to be filed in the coming days. The data breach was discovered on November 15, 2024, when an unsecured Elasticsearch database was identified that had been exposed online for more than 6 weeks between September 19, 2024, and November 5, 2024. The database contained the data of approximately 483,000 Catholic Health patients, including names, dates of birth, Social Security numbers, medical/health information, treatment information, health insurance information, and email/usernames and accompanying passwords. The affected individuals started to be notified about the data breach on...



