News
Amazon's One Medical Seniors Hit by ShinyHunters Extortion Group: 8.8TB of Legacy Patient Data at Risk · Data BreachOpenLoop Health Telehealth Infrastructure Vendor Breach Exposes Patient Data Across Multiple Digital Health Clients · Data BreachHealthcare AI Vendor Xsolis Breach Exposes 1.4 Million Records Across Seven Hospital Systems Including Mayo Clinic · Data BreachHHS Breach Portal Backlog: OCR Still Adding March 2026 Breaches in Late June — What the Delay Means for Compliance Teams · AnalysisKettering Health Refused to Pay the Ransom. The Data Leaked Anyway: What 1.7 Million Exposed Records Teach About Ransomware and HIPAA · Data BreachOCR Settles Ransomware Investigation with Employer-Sponsored Health Plan for $450,000 · OCR EnforcementWhy a Third of Healthcare Breaches Now Trace Back to a Vendor: A Mid-Year 2026 Analysis · AnalysisFrom 4 Million to 60+ Million: The Conduent Breach Shows How Far Third-Party Risk Reaches · Data BreachNYC Health + Hospitals Breach: 1.8 Million Records Exposed via Third-Party Vendor, Including Biometric Data · Data BreachWhen Your Vendor Is the Breach: Millions of Patient Records Just Hit the HHS Tracker, and the Common Thread Is Third-Party Risk · Data BreachDo I Need a BAA With My Vendor? A Plain-English Guide to Which Vendors Require a Business Associate Agreement · Business AssociatesAmazon's One Medical Seniors Hit by ShinyHunters Extortion Group: 8.8TB of Legacy Patient Data at Risk · Data BreachOpenLoop Health Telehealth Infrastructure Vendor Breach Exposes Patient Data Across Multiple Digital Health Clients · Data BreachHealthcare AI Vendor Xsolis Breach Exposes 1.4 Million Records Across Seven Hospital Systems Including Mayo Clinic · Data BreachHHS Breach Portal Backlog: OCR Still Adding March 2026 Breaches in Late June — What the Delay Means for Compliance Teams · AnalysisKettering Health Refused to Pay the Ransom. The Data Leaked Anyway: What 1.7 Million Exposed Records Teach About Ransomware and HIPAA · Data BreachOCR Settles Ransomware Investigation with Employer-Sponsored Health Plan for $450,000 · OCR EnforcementWhy a Third of Healthcare Breaches Now Trace Back to a Vendor: A Mid-Year 2026 Analysis · AnalysisFrom 4 Million to 60+ Million: The Conduent Breach Shows How Far Third-Party Risk Reaches · Data BreachNYC Health + Hospitals Breach: 1.8 Million Records Exposed via Third-Party Vendor, Including Biometric Data · Data BreachWhen Your Vendor Is the Breach: Millions of Patient Records Just Hit the HHS Tracker, and the Common Thread Is Third-Party Risk · Data BreachDo I Need a BAA With My Vendor? A Plain-English Guide to Which Vendors Require a Business Associate Agreement · Business Associates
resolution agreement

Health Information Privacy: Corrective action / RA

Resolution ,

Penalty

Corrective action / RA

Action type

Resolution agreement

Entity profile

Case number

What went wrong

Health Information Privacy

  • Health Information Privacy I would like info on ... Parental AccessHIPAA Security Rule NPRMConfidentiality of Substance Use Disorder (SUD) Patient RecordsChange Healthcare Cybersecurity Incident-FAQs HIPAA for Individuals We offer information about your rights under HIPAA and answers to frequently asked questions about the HIPAA Rules. Filing a Health Information Privacy Complaint You may file a c

Full description

Health Information Privacy I would like info on ... Parental AccessHIPAA Security Rule NPRMConfidentiality of Substance Use Disorder (SUD) Patient RecordsChange Healthcare Cybersecurity Incident-FAQs HIPAA for Individuals We offer information about your rights under HIPAA and answers to frequently asked questions about the HIPAA Rules. Filing a Health Information Privacy Complaint You may file a complaint with OCR if you believe your health information privacy rights under the HIPAA Rules or the regulations protecting confidentiality of substance use disorder patient records were violated. Substance Use Disorder Patient Confidentiality Find information about the requirements to protect confidentiality of substance use disorder patient records, patient rights, and more. HIPAA for Professionals Find information about the HIPAA Rules, guidance on compliance, OCR's enforcement activities, frequently asked questions, and more. Conscience and Religious Freedom HHS enforces federal laws that protect conscience and the free exercise of religion and prohibit coercion and religious discrimination in health and human services. Civil Rights HHS enforces federal civil rights laws that protect the rights of individuals and entities from unlawful discrimination on the basis of race, color, national origin, disability, age, or sex in health and human services. Office for Civil Rights The Office for Civil Rights (OCR) ensures equal access to certain health and human services and protects the privacy and security of health information. Newsroom Read the latest HIPAA news and bulletins, and an archive of past releases. Other Languages Español (Spanish), 繁體中文 (Chinese - Traditional), 简体中文 (Chinese – Simplified), Tiếng Việt (Vietnamese), 한국어 (Korean), Tagalog (Tagalog), Русский (Russian), العربية (Arabic), Français (French), Português (Portuguese), Kreyòl Ayisyen (French Creole), Polski (Polish), Italiano (Italian), Deutsch (German), 日本語 (Japanese), فارسی (Farsi)

Timeline

  • Resolution,
  • Incident and investigation milestones are not consistently published by OCR in machine-readable form.

Key takeaways for your organization

  • Treat internet-facing systems and vendor-hosted environments as in-scope for HIPAA risk analysis and technical safeguards testing.
  • Pair technical access controls with workforce training, sanctions, and proactive audit reviews for inappropriate access patterns.
  • Maintain an actionable risk analysis tied to remediation milestones; evidence should map to Security Rule implementation specifications.
  • Align policies, procedures, and evidence with the specific CFR provisions cited in OCR resolutions affecting your entity type.

Related actions

Source

U.S. Department of Health and Human Services release

Source: U.S. Department of Health and Human Services, Office for Civil Rights. medcomply.ai aggregates public materials for educational use, not legal advice.