settlement
HHS announces first HIPAA breach settlement involving less than 500 patients: Corrective action / RA
Resolution Dec 2012
Penalty
Corrective action / RA
Action type
Settlement
Entity profile
—
Case number
—
What went wrong
HHS announces first HIPAA breach settlement involving less than 500 patients
Timeline
- ResolutionDec 2012
- Incident and investigation milestones are not consistently published by OCR in machine-readable form.
Key takeaways for your organization
- Align policies, procedures, and evidence with the specific CFR provisions cited in OCR resolutions affecting your entity type.
- Run tabletop exercises for breach response, OCR inquiry handling, and privilege-preserving communications with counsel.
- Revisit business associate inventory and downstream vendor security assurances after major enforcement themes in your sector.
Related actions
HHS’ Office for Civil Rights Settles HIPAA Ransomware Security Rule Investigation with BST & Co. CPAs, LLP
—
,
HHS’ Office for Civil Rights Settles HIPAA Ransomware Investigation with Syracuse ASC
—
,
HHS’ Office for Civil Rights Settles HIPAA Privacy and Security Rule Investigation with a Behavioral Health Provider
—
,
Source
U.S. Department of Health and Human Services release
Source: U.S. Department of Health and Human Services, Office for Civil Rights. medcomply.ai aggregates public materials for educational use, not legal advice.