News
Aesto Health AWS Breach Hits HHS Portal at 9.54 Million Patients Across 30 Provider Clients, Including Everside Health · Data BreachTheGentlemen Ransomware Group Threatens Nutex Health's 27-Hospital Network; Class Action Filed Days After SEC Disclosure · Data BreachOCR Settles with California Eye Care Provider Azul Vision for Failure to Provide Timely Patient Record Access — 55th Right of Access Enforcement Action · OCR EnforcementShinyHunters Claims Leak of 7.1 Million Baxter International Salesforce Records Including Patient PII · Data BreachCareCloud EHR Vendor Breach Exposes Medical and Financial Data of 345,000 Patients · Data BreachOptalis Management Solutions and Other HIPAA-Regulated Entities Disclose Patient Data Breaches Affecting Thousands · Data BreachFive Small Healthcare Organizations Disclose Patient Data Breaches: Family Medical Associates of Raleigh, Arkansas Oral & Maxillofacial Surgeons, Alpine Agency of the Midlands, Princeton Family Eye Care, and Others · Data BreachAesto Health AWS Breach Hits HHS Portal at 9.54 Million Patients Across 30 Provider Clients, Including Everside Health · Data BreachTheGentlemen Ransomware Group Threatens Nutex Health's 27-Hospital Network; Class Action Filed Days After SEC Disclosure · Data BreachOCR Settles with California Eye Care Provider Azul Vision for Failure to Provide Timely Patient Record Access — 55th Right of Access Enforcement Action · OCR EnforcementShinyHunters Claims Leak of 7.1 Million Baxter International Salesforce Records Including Patient PII · Data BreachCareCloud EHR Vendor Breach Exposes Medical and Financial Data of 345,000 Patients · Data BreachOptalis Management Solutions and Other HIPAA-Regulated Entities Disclose Patient Data Breaches Affecting Thousands · Data BreachFive Small Healthcare Organizations Disclose Patient Data Breaches: Family Medical Associates of Raleigh, Arkansas Oral & Maxillofacial Surgeons, Alpine Agency of the Midlands, Princeton Family Eye Care, and Others · Data Breach
resolution agreement

Health Information Privacy: Corrective action / RA

Resolution ,

Penalty

Corrective action / RA

Action type

Resolution agreement

Entity profile

Case number

What went wrong

Health Information Privacy

  • Health Information Privacy I would like info on ... Parental AccessHIPAA Security Rule NPRMConfidentiality of Substance Use Disorder (SUD) Patient RecordsChange Healthcare Cybersecurity Incident-FAQs HIPAA for Individuals We offer information about your rights under HIPAA and answers to frequently asked questions about the HIPAA Rules. Filing a Health Information Privacy Complaint You may file a c

Full description

Health Information Privacy I would like info on ... Parental AccessHIPAA Security Rule NPRMConfidentiality of Substance Use Disorder (SUD) Patient RecordsChange Healthcare Cybersecurity Incident-FAQs HIPAA for Individuals We offer information about your rights under HIPAA and answers to frequently asked questions about the HIPAA Rules. Filing a Health Information Privacy Complaint You may file a complaint with OCR if you believe your health information privacy rights under the HIPAA Rules or the regulations protecting confidentiality of substance use disorder patient records were violated. Substance Use Disorder Patient Confidentiality Find information about the requirements to protect confidentiality of substance use disorder patient records, patient rights, and more. HIPAA for Professionals Find information about the HIPAA Rules, guidance on compliance, OCR's enforcement activities, frequently asked questions, and more. Conscience and Religious Freedom HHS enforces federal laws that protect conscience and the free exercise of religion and prohibit coercion and religious discrimination in health and human services. Civil Rights HHS enforces federal civil rights laws that protect the rights of individuals and entities from unlawful discrimination on the basis of race, color, national origin, disability, age, or sex in health and human services. Office for Civil Rights The Office for Civil Rights (OCR) ensures equal access to certain health and human services and protects the privacy and security of health information. Newsroom Read the latest HIPAA news and bulletins, and an archive of past releases. Other Languages Español (Spanish), 繁體中文 (Chinese - Traditional), 简体中文 (Chinese – Simplified), Tiếng Việt (Vietnamese), 한국어 (Korean), Tagalog (Tagalog), Русский (Russian), العربية (Arabic), Français (French), Português (Portuguese), Kreyòl Ayisyen (French Creole), Polski (Polish), Italiano (Italian), Deutsch (German), 日本語 (Japanese), فارسی (Farsi)

Timeline

  • Resolution,
  • Incident and investigation milestones are not consistently published by OCR in machine-readable form.

Key takeaways for your organization

  • Treat internet-facing systems and vendor-hosted environments as in-scope for HIPAA risk analysis and technical safeguards testing.
  • Pair technical access controls with workforce training, sanctions, and proactive audit reviews for inappropriate access patterns.
  • Maintain an actionable risk analysis tied to remediation milestones; evidence should map to Security Rule implementation specifications.
  • Align policies, procedures, and evidence with the specific CFR provisions cited in OCR resolutions affecting your entity type.

Related actions

Source

U.S. Department of Health and Human Services release

Source: U.S. Department of Health and Human Services, Office for Civil Rights. medcomply.ai aggregates public materials for educational use, not legal advice.