OSHA Confirms 2025 Increase to Maximum Violation Penalties
The Occupational Safety and Health Administration (OSHA) has increased the maximum civil monetary penalty amounts for violations in 2025, which apply to all civil monetary penalties assessed on or after January 15, 2025. Each year, the civil monetary penalties for violations are increased pursuant to the Federal Civil Penalties Inflation Adjustment Act of 1990, as amended by the Federal Civil Penalties Inflation Adjustment Act Improvements Act of 2015 to ensure that the deterrent effect of the civil monetary penalties is maintained. This year, the penalties have been increased by applying the inflation multiplier of 1.02598 set by the Office of Management and Budget (OMB) – a percentage increase of 2.6% for 2025. The new penalty amounts for 2025 are detailed in the table below. Type of Violation 2024 Maximum Penalty 2024 Maximum Penalty Serious Other Than-Serious Posting Requirements $16,131 per violation $16,550 per violation Failure to Abate $16,131 per day beyond the abatement date $16,550 per day beyond the abatement date Willful or Repeated $161,323 per violation $165,514 per...
State Of HIPAA – 2027 Predictions
It has been three decades since President Clinton signed the Health Insurance Portability and Accountability Act (HIPAA) into law in 1996, and a quarter of a century has passed since the HIPAA Privacy Rule took effect, yet HIPAA compliance is still proving a challenge for many HIPAA-regulated entities. Noncompliance with the HIPAA Rules is frequently identified by the HHS Office for Civil Rights (OCR) and state attorneys general in compliance audits and investigations of complaints and data breaches. Over the past 25 years, the HIPAA Rules have been updated on multiple occasions, and there are pending changes to the HIPAA Privacy and Security Rules that are due to be finalised in the next 18 months, the first of which is due in August 2026. This article explores the current state of HIPAA compliance and some of the key aspects of the HIPAA Rules that are proving difficult for HIPAA-regulated entities, along with predictions for 2026 and 2027. HIPAA Predictions for 2026 and 2027 A final rule implementing changes to the HIPAA Privacy Rule to improve care coordination is pencilled in...
What did the HIPAA Omnibus Rule Mandate?
The HIPAA Omnibus Rule mandated modifications to the Privacy, Security, and Enforcement Rules in order to adopt measures passed in the HITECH Act, finalized the Breach Notification Rule, and added standards to account for the passage of the GINA Act. The key provisions of the HIPAA Omnibus Rule were: Make business associates of covered entities directly liable for HIPAA compliance. Strengthen the limitations on uses and disclosures of Protected Health Information. Expand individuals’ rights to restrict disclosures of Protected Health Information. Expand individuals’ rights to request copies of their Protected Health Information. Require modifications to – and require redistribution of – Notices of Privacy Practices. Modify the authorization requirements for disclosures of Protected Health Information. The adoption of a four-tired civil monetary penalty structure for violations of HIPAA. The finalization of the Breach Notification Rule and the revised “harm” threshold. The addition of standards to account for the passage of the GINA Act 2008. What was the HIPAA Omnibus...
Is Acuity HIPAA Compliant?
Acuity is HIPAA compliant for covered entities and business associates that subscribe to a HIPAA-enabled Powerhouse or Enterprise account, configure the account to support HIPAA compliance, and disable non-compliant integrations and services. Depending on if and how payments are accepted via Acuity, it may also be necessary to change payment processors. Acuity is a versatile online scheduling solution that was acquired by Squarespace in 2019. Acuity Scheduling can be used with – or independently of – Squarespace websites to schedule appointments, send automated text and email reminders, and process payments. It also integrates with many client engagement, video conferencing, and accounting solutions to increase productivity and efficiency. When using Acuity to create, receive, store, or transmit personal information that is considered Protected Health Information (PHI) under HIPAA, it is necessary for Acuity to be HIPAA compliant. Acuity states it supports HIPAA compliance, but only under certain conditions. These conditions include subscribing to a Powerhouse or...
Eskenazi Health Pays $2.5 Million to Resolve Class Action Data Breach Lawsuit
Eskenazi Health has agreed to settle litigation stemming from an August 2021 ransomware attack in which the protected health information of more than 1.5 million patients was compromised. The ransomware attack was detected on or around August 4, 2024, when files were encrypted on its systems. The forensic investigation confirmed that a ransomware group first accessed its systems on May 19, 2021, and disabled its security systems, allowing them to remain in its network undetected. The initial investigation found no evidence of data theft; however, data exfiltration was later identified. Data stolen in the attack included names, addresses, telephone numbers, email addresses, dates of birth, medical record numbers, patient account numbers, diagnoses, clinical information, insurance information, prescriptions, driver’s license numbers, passport numbers, face photographs, Social Security numbers, and credit card information. Patients were notified about the data breach in November 2021 and were offered complimentary credit monitoring services. Eskenazi Health was able to recover the...



