Featured insight
OCR Enforcement
Deer Oaks, a behavioral health provider, made patient discharge summaries publicly accessible online, exposing names, dates of birth, and diagnoses. OCR's $225,000 settlement is a warning about accidental public exposure and the special sensitivity of behavioral health data.
6 min readUpdated Jun 18, 2026
Read articleOCR Enforcement
OCR reached a $450,000 settlement with an employer-sponsored group health plan after a 2021 ransomware attack exposed PHI for more than 10,000 plan members. Here is what HR leaders and benefits plan administrators need to know.
Updated Jun 18, 20267 min read
OCR Enforcement
Cadia Healthcare posted patient names, photos, and treatment details as 'success stories' on their public website without HIPAA authorization. OCR's investigation found 150 patients affected and fined the facility group $182,000. Here is what every healthcare marketing team needs to know.
Updated Jun 1, 20267 min read
OCR Enforcement
BST and Co. CPAs, a New York public accounting firm, settled with OCR for a ransomware breach affecting patient financial data. The case is a warning for every professional services firm that handles healthcare client data.
Updated May 31, 20266 min read
OCR Enforcement
OCR fined MMG Fusion just $10,000 for exposing 15 million patients' data — the company has since dissolved. The real story is what this means for every dental practice that trusted them with patient data.
Updated May 31, 20266 min read
OCR Enforcement
Top of the World Ranch Treatment Center paid $103,000 to settle HIPAA violations after a 2023 phishing attack exposed patient records. OCR found the center had never completed a HIPAA Security Rule risk analysis.
Updated May 15, 20264 min read
OCR Enforcement
OCR's 54th Right of Access enforcement action settled with Concentra Inc. for $112,500 after a patient had to make six separate records requests over more than a year before receiving access to his health information.
Updated May 14, 20266 min read
OCR Enforcement
Warby Parker's HIPAA penalty came down to one overlooked requirement. Here is what happened, what OCR actually fined them for, and how to avoid the same mistake.
Updated May 12, 20266 min read
OCR Enforcement
OCR has now resolved more than 50 HIPAA enforcement actions in 2026 under its Risk Analysis and Right of Access initiatives. A new enforcement focus on parental access to minor records adds a third priority area every practice must understand.
Updated May 11, 20266 min read
OCR Enforcement
What OCR actually asks for in an audit, the documents to have ready now, and the gaps that trigger findings. A practical preparation guide for healthcare organizations.
Updated May 11, 20269 min read
OCR Enforcement
HHS published updated HIPAA civil money penalty amounts effective January 2026. Here are the current figures for all four violation tiers and what they mean for your compliance program.
Updated May 8, 20266 min read
OCR Enforcement
An employer health plan drew a $245K HIPAA penalty. What went wrong, why employee PHI is a blind spot, and what plan sponsors need to know.
Updated May 5, 20266 min read
OCR Enforcement
OCR's settlement with Assured Imaging highlights two compounding violations: no risk analysis ever conducted and delayed breach notification. Here is what every covered entity must learn from this case.
Updated May 3, 20265 min read
OCR Enforcement
OCR announced four simultaneous HIPAA settlements on April 23, 2026 totaling $1.165 million following ransomware investigations. All four failed the same requirement.
Updated Apr 30, 20265 min read