Health Law Daily Wrap Up, HIPAA—SETTLEMENT AGREEMENTS: OCR settles HIPAA cybersecurity investigation with small health care provider, (May 30, 2025)
By Susan L. Smith, JD, MA
The HHS Office for Civil Rights (OCR) has entered into a Resolution Agreement with a small California health care provider to resolve potential violations of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Breach Notification and Security Rules.
The Office for Civil Rights (OCR) has reached a settlement with a California health care provider that conducts magnetic resonance imaging and related services to resolve potential violations of the Health Insurance Portability and Accountability Act (HIPAA) and Breach Notification and Security Rules. The OCR initiated a compliance review of the provider after learning that it experienced a breach of protected health information (PHI) stored on its Picture Archiving and Communication System (PACS) server for storing, retrieving, managing, and accessing radiology images due to an unauthorized third party’s impermissible access. According to a press release, the OCR obtained information alleging that PHI maintained or stored by the provider was accessible via the internet and disclosed as a result of an unsecure PACs server. The investigation revealed that the provider had never conducted a HIPAA risk analysis and it failed to complete timely breach notification within 60 days of discovering the breach of an unsecured server containing the medical images of 21,778 individuals, The provider agreed to pay HHS $25,000 (Resolution Amount) and has entered into and agreed to comply with a Corrective Action Plan (CAP) that will be monitored by OCR for two years. If the provider breaches the CAP, the provider will be in breach of the Agreement (Resolution Agreement, May. 12, 2025).
Risk Analysis and Breach Notification Rules. The Risk Analysis provision of the Security Rule requires a regulated organization to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information (ePHI) held by that organization. The Breach Notification Rule requires HIPAA covered entities and their business associates to provide notification following a breach of unsecured protected health information.
Corrective Action Plan. The CAP includes the following requirements:
Breach notification. Within 60 calendar days of the Effective Date, the provider will submit a draft breach notification to all individuals whose PHI was maintained on the PACS server before it was secured in December 2020 in a manner consistent with the regulation requirements. Upon OCR’s approval of the breach assessment and breach notification, the provider must issue the approved individual notification to affected individuals and provide evidence of this notification to HHS. Within 60 days of the Effective Date, the provider will provide draft media notification to OCR. Upon OCR’s approval, the provider will provide the approved media notification related to the breach of PHI that was maintained on the PACs server before it was secured in December 2020 in a manner consistent with the regulations. VUM shall provide evidence of this notification and the identity of the media outlets.
Risk analysis. The provider will conduct and complete an accurate analysis of security risks and vulnerabilities that includes all electronic equipment, data systems, programs and applications controlled or shared by the provider that contain, store, transmit or receive electronic equipment that contain or store ePHI that will then be incorporated in its risk analysis. The provider will submit the scope and methodology by which it proposes to conduct the risk analysis to HHS within 60 days and provide evidence it completed the risk analysis after its methodology has been approved by HHS.
Risk management plan. The provider must develop an enterprise-wide risk management plan to address and mitigate any security risks and vulnerabilities identified in the risk analysis.
Policies and procedures. The provider must develop, maintain, and revise, as necessary, written policies and procedures to comply with the Federal Standards for the Privacy of Individually Identifiable Health Information and the Security Standards for the Protection of Electronic Protected Health Information and the Breach Notification for Unsecured Protected Health Information Regulations. The provider must provide the policies and procedures to HHS within 60 calendar days of receipt of HHS’ approval of the risk management plan. Upon receiving HHS’ notice of required revisions the provider must revise the policies and procedures accordingly and provide the revised policies and procedures to HHS for review and approval. When approved the policies and procedures must be implemented and then distributed to members of the workforce who have access to ePHI.
Reportable events. The provider must promptly investigate when a workforce member likely failed to comply with policies and procedures. If after investigation the provider determines the member of the workforce failed to comply with policies and procedures, the provider must report the event to HHS.
Training. The provider must provide HHS with copies of the training material on privacy and security of PHI and make any revisions if necessary. Upon approval, the provider must provide training to workforce members who have access to PHI.
Implementation Report and Annual Reports. Within 120 calendar days after policies and procedures are approved, the provider will submit a written report to HHS summarizing the status of the implementation of the requirements of the CAP. For each one year period after the effective date, the provider will submit a report regarding its compliance with the CAP.
CIAsSettlementAgreements: SettlementAgreementsNews ConfidentialityNews CyberPrivacyFeed HITNews HIPAANews DataPrivacy DataSecurity DataBreach LitigationEnforcement