Go to Wolters Kluwer VitalLaw.comGo to Wolters Kluwer VitalLaw.com
VitalLaw®
  • Find answers to your questions
  • Log in to access your subscriptions
In depth. On point.
In depth. On point.
  • Home
  • Legal Directory
  • Home
  • Legal Directory
In depth. On point.
  • Articles
  • Articles
  • Law Firms
  • Law Firms
  • Organizations
  • Organizations
    • GENERAL HEALTH CARE NEWS—E.D.N.Y.: Surgery practice’s challenge to No Surprises Act dismissed
    • ADMINISTRATION OF MEDICARE/MEDICAID PROGRAMS—DAB DECISIONS: DMEPOS Supplier had no right to review duration of CMS revocation
    • ADMINISTRATION OF THE FDC ACT—NOTICES: FDA revokes EUAs for multiple COVID-19 tests approved during the COVID-19 pandemic
    • ADVERTISING (FOOD, DRUG & MEDICAL DEVICES)—N.D. Cal.: Class certification denied in consumer protection case over ghee food labels
    • AUDITS AND MONITORING—OIG REPORTS: HHS falls short of full compliance with PIIA for FY 2024
    • CONTROLLED SUBSTANCES—NOTICES: Importer debarred for selling non-FDA approved drugs
    • ELECTRONIC HEALTH RECORDS—SETTLEMENT AGREEMENTS: Medical Record Data Breach Leads to Fine for Health Care Provider
    • EXPERT INSIGHTS: CMS to immediately begin auditing Medicare Advantage plans in significant expansion of enforcement efforts
    • GENERAL HEALTH CARE NEWS—GAO REPORTS: GAO addresses Congress’ concerns regarding caregiving youth issues
    • HEALTH CARE EMPLOYMENT ISSUES—D. Md.: Evidentiary requests denied in COVID-19 vaccine mandate religious discrimination case
    • HEALTH CARE EMPLOYMENT ISSUES—W.D. Va.: Lawsuit alleging COVID-19 vaccine religious discrimination dismissed in part
    • HIPAA—SETTLEMENT AGREEMENTS: OCR settles HIPAA cybersecurity investigation with small health care provider
    • LAW FIRM NEWS—Noteworthy developments in the legal community
    • MISBRANDING (FOOD, DRUGS & MEDICAL DEVICES)—NOTICES: Importer debarred for offering for sale misbranded male enhancement drugs
  • Articles
  • Articles
  • Law Firms
  • Law Firms
  • Organizations
  • Organizations

    Health Law Daily Wrap Up, ELECTRONIC HEALTH RECORDS—SETTLEMENT AGREEMENTS: Medical Record Data Breach Leads to Fine for Health Care Provider, (May 30, 2025)

    Organizations Mentioned:Baycare Health System

    By Patricia K. Ruiz, J.D.

    The breach occurred when a non-clinical former staff member’s credentials were used to access patient records.

    The U.S. Department of Health and Human Services’ Office for Civil Rights (OCR) has entered into a settlement with Florida hea ...

    By Patricia K. Ruiz, J.D.

    The breach occurred when a non-clinical former staff member’s credentials were used to access patient records.

    The U.S. Department of Health and Human Services’ Office for Civil Rights (OCR) has entered into a settlement with Florida health care provider BayCare Health System, resolving alleged violations of the Health Insurance Portability and Accountability Act (HIPAA) security rule, OCR announced (Resolution Agreement, Feb. 14, 2025).

    The OCR began an investigation after it received a complaint alleging that, after the complainant received treatment at a BayCare facility, she was contacted by an unknown individual with photos of her printed medical records and a video of someone scrolling through her medical records on a computer screen. The OCR determined the credentials used to access the complainant’s medical records belonged to a former non-clinical staff member of a physician’s practice, which had access to BayCare’s electronic medical records.

    The OCR determined that BayCare potentially violated multiple requirements of the HIPAA security rule, including (1) failure to implement policies and procedures for authorizing access to electronic protected health information (ePHI) consistent with the applicable requirements of the HIPAA privacy rule; (2) failure to reduce risks and vulnerabilities to ePHI to a reasonable and appropriate level; and (3) failure to regularly review records of information system activity.

    The settlement requires BayCare to implement a corrective action plan, to pay OCR $800,000, and to take steps to resolve its potential HIPAA security rule violations. The settlement also requires BayCare to protect the privacy and security of ePHI by, among other things, conducting a thorough risk analysis to determine potential risks and vulnerabilities to the confidentiality, integrity, and availability of its ePHI.

    CIAsSettlementAgreements: SettlementAgreementsNews ConfidentialityNews EHRNews HITNews HIPAANews

    © 2026 CCH Incorporated and its affiliates and licensors. All rights reserved.

    • Manage Cookie Preferences
    • Privacy Statement
    • Terms of Use