5 HIPAA Compliance Examples
Although a search for HIPAA compliance examples most often returns results listing HIPAA violations, if you look deep enough it is possible to find multiple examples of HIPAA compliance, workplaces designed to support HIPAA compliance, and policies that explain why compliance with HIPAA is important. Further HIPAA compliance examples can be found by comparing the compliance efforts of one organization against those of another, or by identifying organizations that implement HIPAA policies with more stringent requirements than those demanded by the HIPAA Privacy Rule in order to mitigate the likelihood of foreseeable and impermissible disclosures of Protected Health Information (PHI). Dealing with Complaints Privately In 2019, Elite Dental Associates settled an alleged HIPAA violation for $10,000 after admitting to impermissibly disclosing PHI in a response to a negative online review. Some dental practices did not learn from the settlement, and continued to impermissibly disclose PHI on review sites – leading to two further settlements in 2022 in which the practices were fined...
OCR Settles Ransomware Investigation With Michigan Surgical Group for $10,000
Another ransomware investigation has been settled by the HHS’ Office for Civil Rights (OCR) with a financial penalty. Northeast Surgical Group, P.C, a Michigan-based provider of surgical services, has agreed to pay $10,000 to resolve a potential violation of the HIPAA Security Rule – The failure to conduct a comprehensive and accurate risk analysis to identify risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information (ePHI). On March 6, 2023, Northeast Surgical Group notified OCR that the ePHI of 15,298 patients on its network had been encrypted in a ransomware attack. The forensic investigation confirmed that the ransomware group exfiltrated files containing patient information before ransomware was used to encrypt files. Its entire patient population had potentially been affected. OCR investigated the data breach to determine if Northeast Surgical Group was compliant with the HIPAA Rules and determined that Northeast Surgical Group had failed to conduct a HIPAA-compliant risk analysis. This was OCR’s 10th enforcement...
HIPAA Compliance in Multi-Site Medical Practices
The challenge of HIPAA compliance in multi-site medical practices is that different sites can have different approaches to governance, risk management, and HIPAA compliance – making it difficult for employees working in different sites to comply with each site’s policies and procedures. One way to overcome this challenge is to use multilocation HIPAA compliance management software to standardize policies and procedures. It is not unusual for healthcare organizations to operate across multiple sites. Even smaller medical practices can have separate offices for primary care, outpatient surgeries, and medical specialties. In such circumstances, it is often the case that each site conducts separate assessments for facility risks, clinical risks, emergency planning, etc., and develops its own policies and procedures to mitigate the risks and respond to incidents. However, what might be assessed as a risk in one location might not be assessed as a risk in another. For example, if a multi-site medical practice has separate offices for psychiatry and podiatry, the psychiatry office...
Hapy Bear Surgery Center Agrees to Settle Data Breach Lawsuit
A class action lawsuit filed against Hapy Bear Surgery Center over a December 2023 ransomware attack has been settled for an undisclosed sum. The Tulare, California pediatric dental clinic identified the cyberattack on or around December 27, 2024, and confirmed on March 19, 2024, that names, addresses, medical information, health insurance information, Social Security numbers, and driver’s license numbers had potentially been accessed or stolen. Notification letters were issued in April 2024. A class action lawsuit – In re: Hapy Bear Surgery Center Data Security Incident Litigation – was filed in California Superior Court for Tulare County over the data breach. The plaintiffs alleged that the dental clinic was negligent by failing to implement appropriate safeguards to ensure the confidentiality of patient data. The lawsuit also asserted claims of breach of implied contract, unjust enrichment, unfair business practices, and a violation of the California Confidentiality of Medical Information Act. Hapy Bear Surgery Center denies all claims and maintains that it did nothing...
Memorial Healthcare System Settles Alleged HIPAA Right of Access Violation
South Broward Hospital District, a Florida health system that does business as Memorial Healthcare System, has agreed to settle an alleged violation of the HIPAA Right of Access with the U.S. Department of Health and Human Services’ Office for Civil Rights (OCR). The HIPAA Privacy Rule gives individuals rights over their health records, including the right to obtain a copy of those records and to only be charged a reasonable cost-based fee. When a HIPAA-regulated entity receives a request, the records must be provided within 30 days, or in limited circumstances, a 30-day extension is possible. OCR received a complaint from a patient on June 23, 2021, who alleged he had submitted a request to Memorial Healthcare System on April 26, 2021, for a copy of specific health records but those records had not been provided. OCR investigated and found that while the patient had mailed a written request for the records on April 26, 2021, it was not the first time the records had been requested. The patient had requested a copy of an EEG tracing via the Memorial Healthcare System patient portal...



