settlement
HHS Office for Civil Rights Settles HIPAA Ransomware Cybersecurity Investigation for $10,000: $10,000
Resolution Jan 2025
Penalty
$10,000
Action type
Settlement
Entity profile
—
Case number
—
What went wrong
HHS Office for Civil Rights Settles HIPAA Ransomware Cybersecurity Investigation for $10,000
Timeline
- ResolutionJan 2025
- Incident and investigation milestones are not consistently published by OCR in machine-readable form.
Key takeaways for your organization
- Align policies, procedures, and evidence with the specific CFR provisions cited in OCR resolutions affecting your entity type.
- Run tabletop exercises for breach response, OCR inquiry handling, and privilege-preserving communications with counsel.
- Revisit business associate inventory and downstream vendor security assurances after major enforcement themes in your sector.
Related actions
Health Care Provider Pays $100,000 Settlement to OCR for Failing to Implement HIPAA Security Rule Requirements
—
$100,000
Lab Pays $16,500 Settlement to HHS, Resolving Potential HIPAA Violation over Medical Records Request
GA
$16,500
HHS Civil Rights Office Resolves HIPAA Right of Access Investigation with $20,000 Settlement
FL
$20,000
Source
U.S. Department of Health and Human Services release
Source: U.S. Department of Health and Human Services, Office for Civil Rights. medcomply.ai aggregates public materials for educational use, not legal advice.