Category: HIPAA Enforcement

  • Cybersecurity & HIPAA Compliance: Ransomware Enforcement Cases

    How Ransomware Is Driving OCR Enforcement

    What is the connection between cybersecurity and HIPAA?

    Cybersecurity is a core requirement of HIPAA compliance. The HIPAA Security Rule mandates that healthcare organizations implement administrative, technical, and physical safeguards to protect electronic protected health information (ePHI).

    As ransomware attacks increase, regulators now treat weak cybersecurity controls as direct HIPAA violations, not just IT failures.

    Why is ransomware increasing HIPAA enforcement?

    Ransomware incidents often expose gaps in compliance programs. When attackers encrypt or steal ePHI, the Office for Civil Rights (OCR)investigates whether the organization:

    • Conducted a risk analysis
    • Implemented access controls
    • Maintained system security and patching
    • Documented safeguards

    If these are missing, fines and settlements are likely, even if the attack itself was external.

    How Ransomware Is Reshaping HIPAA Compliance

    Ransomware has made healthcare one of the most targeted sectors for cyberattacks. As a result, HIPAA compliance now requires continuous cybersecurity risk management, not just annual documentation.

    OCR enforcement trends show that organizations are penalized most often for:

    • Failure to perform a risk analysis
    • Lack of multi-factor authentication (MFA)
    • Unpatched systems or outdated software
    • Insufficient audit controls and monitoring

    These findings confirm that cybersecurity weaknesses directly translate into HIPAA Security Rule violations.

    OCR Enforcement Examples and Common Violations

    1. Lack of Risk Analysis

    OCR consistently identifies missing or incomplete risk assessments as a top violation. Organizations must demonstrate they actively identify and mitigate risks.

    What is a Security Risk Assessment?

    A proper risk analysis is not optionalโ€”it is the foundation of HIPAA compliance.

    2. Weak Access Controls

    Ransomware attackers commonly exploit poor authentication and user access management. OCR frequently cites:

    • No MFA
    • Shared logins
    • Excessive user privileges

    3. Inadequate System Security

    Failure to patch systems or monitor networks allows ransomware to spread quickly. OCR expects proactive vulnerability management and real-time detection.

    What Cybersecurity Measures Are Required for HIPAA Compliance?

    To meet modern HIPAA expectations, healthcare organizations should implement:

    • Enterprise-wide risk assessments
    • Endpoint detection and response (EDR)
    • Secure, tested backups
    • Email security and phishing prevention
    • Continuous monitoring and audit logging
    • Workforce security training

    These safeguards must be documented and regularly updated.

    How to Align Cybersecurity with HIPAA Requirements

    Organizations must move from reactive compliance to integrated security programs.

    At Colington Consulting we help healthcare organizations align cybersecurity with HIPAA requirements.

    What services are needed to meet HIPAA requirements?

    Our approach combines regulatory expertise with real-world threat protection, reducing both breach risk and enforcement exposure. For additional guidance, visit our HIPAA compliance blog page.

    Key Takeaways

    • Cybersecurity failures are now HIPAA violations
    • Ransomware drives increased OCR enforcement actions
    • Risk analysis is the most commonly cited deficiency
    • Organizations must implement proactive, continuous security controls
    • Compliance now requires operational cybersecurity, not just policies

    FAQ

    Are ransomware-related HIPAA breaches made public by OCR?

    Yes. As required by the HITECH Act, OCR posts on the HHS website a list of breaches of unsecured protected health information affecting 500 or more individuals.

    What is the most common HIPAA violation in ransomware cases?

    Failure to conduct a comprehensive risk analysis is the most frequent violation cited by OCR.

    Does HIPAA require cybersecurity frameworks like NIST?

    HIPAA does not mandate NIST, but OCR expects organizations to follow recognized security standards to meet compliance requirements.

    Schedule a 30 minute HIPAA Risk Review

  • 2025 HIPAA Enforcement Trends So Far: What To Know

    2025 HIPAA Enforcement Trends So Far: What Healthcare Providers Need to Know

    As we enter the month of October, healthcare compliance has faced a new level of scrutiny so far this year. The HHS Office for Civil Rights (OCR), the agency responsible for enforcing HIPAA, is no longer focusing only on isolated breaches. Instead, enforcement is targeting systemic gaps in security and compliance programs, particularly in areas where healthcare providers continue to fall short.

    Risk Analysis Remain the Cornerstone

    OCR has made it clear that a comprehensive, documented security risk analysis (SRA) remains the foundation of HIPAA compliance. Organizations that fail to conduct and regularly update an SRA put themselves at serious enforcement risk. Regulators expect healthcare practices to not only identify vulnerabilities but also take measurable steps to address them. Outdated or incomplete assessments are one of the most common triggers for enforcement actions.

    Ransomware is Now a Compliance Issue

    The dramatic rise in ransomware has changed the enforcement landscape. A cyberattack is no longer viewed as an isolated IT issue โ€” it is now a compliance problem. If inadequate patching, lack of encryption, or a weak incident response plan contribute to a ransomware event, OCR is likely to pursue penalties or corrective action. Healthcare organizations must view ransomware preparedness as both a cybersecurity and a regulatory obligation.

    Modernization of the Security Rule

    HIPAA itself is evolving. Proposed updates to the Security Rule reflect the realities of todayโ€™s threat environment. Multi-factor authentication, encryption, vendor oversight, and formal incident response planning are poised to become explicit requirements rather than best practices. Providers who move early to implement these safeguards will be better positioned to demonstrate compliance when enforcement follows.

    Ongoing Right of Access Enforcement

    OCRโ€™s Right of Access Initiative continues to be one of the agencyโ€™s most active enforcement areas. Patients must be able to access their records quickly and affordably. Practices that delay, overcharge, or fail to provide access face growing regulatory risk. In addition, business associates and third-party vendors are under greater scrutiny as regulators focus on the entire chain of responsibility for protected health information (PHI).

    Overlapping Compliance Pressures

    HIPAA is no longer the only regulatory concern. Telehealth, digital marketing, and state-level privacy laws are creating overlapping obligations. OCR and state attorneys general are increasingly aligned, making it essential for providers to understand and address compliance at both federal and state levels.

    Looking into the Crystal Ball for 2026

    The message from regulators is clear: compliance must be proactive, measurable, and ongoing. Organizations should:

    • Perform and document accurate and thorough security risk analysis.
    • Implement multi-factor authentication and encryption across systems.
    • Ensure Business Associate Agreements are in place, as appropriate for vendors.
    • Maintain and test an incident response plan.
    • Ensure all patientsโ€™ right-of-access requests are handled promptly.

    At the end of the day, OCR is rewarding organizations that can prove their compliance efforts are more than policies on paper. Demonstrable action is the key to avoiding costly enforcement.

    Colington Consulting | HIPAA Compliance, Risk Assessment & Management

    Is your organization ready for HIPAA enforcement? Contact our office today to schedule a free HIPAA compliance review and take the first step toward protecting your organization from regulatory risk.

    Helping Organizations Achieve HIPAA Complianceโ„ข

  • Anthem HIPAA Breach

    Setting the Stage for More Government Oversight

    by Jay Hodes, President – Colington Consulting

    The dust has settled, and more facts have been coming to light regarding the recent HIPAA data breach at Anthem Blue Cross Blue Shield. It was only a matter of time before the U.S. Congress started making some noise about cybersecurity. Within days of news reports of the Anthem breach, the U.S. Senate Committee on Health, Education, Labor and Pensions announced a bipartisan initiative to focus on the security of health information technology. This initiative will also look at the health industryโ€™s overall preparedness for cyber threats.

    Although the timing was ironic and clearly not related to the Anthem breach, the White House announced its 2016 proposed budget that includes an increase in funding for HIPAA compliance programs. The proposed budget indicates around a 10% percent increase in funding for the Office for Civil Rights (OCR). OCR is the agency within the U.S. Department of Health and Human Services (HHS) with HIPAA compliance and oversight responsibilities.

    As far as the possible budget increase for OCR, we will wait to see what type of mood Congress is in to approve this. And, even with this congressional initiative, any proposed fixes will take time and money. In the meantime, hopefully the Anthem case sends a loud and clear message to all healthcare providers to up their game when it comes to protecting patient health information. Healthcare providers, plans and clearinghouses need to go on the offensive and be proactive when it comes to having the proper information technology safeguards in place. The threat of Congressional action or a beefed up OCR must not be the incentive to do so.

    Regrettably, the use of encryption is not a requirement of the HIPAA Security Rule. As shocking as that sounds, that does not mean covered entities do not need to encrypt their patient data. What the guidelines call for, as provided by HHS, is this:

    The encryption implementation specification is addressable, and must therefore be implemented if, after a risk assessment, the entity has determined that the specification is a reasonable and appropriate safeguard in its risk management of the confidentiality, integrity and availability of e-PHI [electronic protected health information]. If the entity decides that the addressable implementation specification is not reasonable and appropriate, it must document that determination and implement an equivalent alternative measure, presuming that the alternative is reasonable and appropriate. If the standard can otherwise be met, the covered entity may choose to not implement the implementation specification or any equivalent alternative measure and document the rationale for this decision.

    It is incumbent on covered entities to conduct a HIPAA Risk Assessment in order to make the determination on whether it is reasonable and appropriate to their particular circumstance to use encryption software. The assessment must be the basis for the decision. And if the decision is made not to encrypt, then the justification must be made abundantly clear in documentation.

    So if there is a breach and OCR asks during an investigation why your organization did not encrypt its protected health information, the justification must be based on a low threat to your data. Make sure you can back that up with documentation that is solid and well-defined. Possible civil and criminal prosecution will be based on the proof you provide.

    Need Help with Your HIPAA Compliance Program?

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

    • This article was updated on June 23, 2026 and reviewed By: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert
    • Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.
  • HIPAA Compliance โ€“ Waiting for the Other Shoe to Drop

    by Jay Hodes, President – Colington Consulting

    The expression โ€œwaiting for the other shoe to dropโ€ appears to have originated in the early 1900โ€™s and is often associated with the arrival of a seemingly inevitable event. I speculate we are at that point in terms of ramped up HIPAA compliance enforcement. The recent Anthem data breach shined a significant spotlight on how vulnerable health information technology can be without the proper safeguards in place.

    The Office for Civil Rights (OCR), the U.S. Department of Health and Human Services agency responsible for HIPAA oversight, has made a lot of noise about being more aggressive in enforcement of the regulations. You would think it is time for the proverbial other shoe to drop. But not so fast. With limited resources, there is only so much OCR can do. That needs to change. It will and probably soon.

    There is now, and has been for a while, a lot at stake in terms of making sure healthcare providers and business associates have safeguards in place to properly secure patientsโ€™ protected health information. If major healthcare plans like Anthem are not making sure they are meeting all the HIPAA required implementation specifications, what can be said for smaller healthcare providers?

    The Ponemon Institute recently released its โ€œFifth Annual Study on Medical Identity Theft.โ€ Among the findings, the study discovered that โ€œconsumers expect healthcare providers to be proactive in preventing and detecting medical identity theft.โ€ What was surprising is that โ€œmany respondents are not confident in the security practices of their healthcare provider.โ€ Another interesting outcome of study was that โ€œ79 percent of respondents say it is important for healthcare providers to ensure the privacy of their health records,โ€ and almost half of those respondents said โ€œthey would consider changing healthcare providers if their medical records were lost or stolen.โ€

    The results of the Ponemon study must be a wakeup call for healthcare providers. Can you afford to have half of your patients leave your practice if a breach occurs? As a healthcare provider, donโ€™t be surprised if patients start asking about how you are securing their protected health information (PHI). With all the recent data breaches in retail stores like Target, Sony PSN and Home Depot, consumers realize the vulnerabilities associated with the use of credit cards. As these same consumers seek healthcare services, it will be only a matter of time before questions are asked about safeguarding PHI.

    As a healthcare provider or business associate, make sure you are doing everything you can to protect health information. It goes way beyond a checklist. A robust HIPAA compliance program must be in place, regardless of the size of your practice or business. If you cannot meet all the HIPAA requirements by doing it in-house, consider outsourcing this responsibility. Take the burden off the plate of your office or practice manager or designated HIPAA officer.

    There is still time before that other shoe drops.

    Need Help with Your HIPAA Compliance Program?

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

  • What Comes Up, Must Go Down: Regulatory Trends and HIPAA

    Enforcement of HIPAA mandates by the HHS Office for Civil Rights (OCR) are more aggressive than ever before, โ€œtotaling $28.7 million from enforcement actionsโ€ in 2018, an increase of 22% from the last record total of $23.5 million in 2016. ย According to an OCR press release, 2018 saw that office establish โ€œan all-time record yearโ€ in HIPAA enforcement activity, settling โ€œ10 casesโ€ and being โ€œgranted summary judgment in a case before an Administrative Law Judge.โ€ One of these 10 cases was the watershed HIPAA settlement with Anthem, Inc. for $16 million.

    OCR Settlements* and Judgement** for 2018

    Jan – FileFax*ย  –ย  $100,000

    Jan – Fresenius Medical Care* – $3,500,000

    Jun – MD Anderson** – $4,348,000

    Augย  – Boston Medical Center*ย  –ย  $100,000

    Sep – Brigham & Womenโ€™s Hospital* – $384,000

    Sep – Mass. General Hospital* – $515,000

    Sep – Advanced Care Hospitalists* – $500,000

    Oct – Allergy Associates of Hartford* – $125,000

    Oct – Anthem, Inc* – $16,000,000

    Nov – Pagosa Springs* – $111,400

    Dec – Cottage Health* – $3,000,000

    Total โ€“ Settlements & Judgement:ย  $28,683,400

    While the current administration did and continues to tout a posture of deregulation, the reality on the ground for organizations that must comply with HIPAA is that OCR has only strengthened its enforcement mechanisms, showing very little tolerance for security and privacy breaches arising from:

    • The mismanagement, or lack of proper storage, transmission, or disposal of patient PHI and ePHI.
    • An incomplete or missing Business Associate Agreement (BAA) made with any and all vendors who might be considered a Business Associates (BA) under HIPAA.
    • Cyberattacks via successful email phishing attempts targeting not just Covered Entity (CE) workers or employees, but also workers or employees of any vendor affiliated with theย  CE.
    • Incompatible or insufficient risk analysis and risk management processes on the part of the CE.

    Out of these 11 instances of verified HIPAA violations,

    • 6 CEs were found to have mismanaged or improperly stored, transmitted, or disposed of patient PHI and ePHI (Fresenius Medical Care North America, FileFax, Inc., MD Anderson, Allergy Associates of Hartford, Pagosa Springs, and Cottage Health)
    • 3 CEs did not have a BAA in place to manage vendors who are considered to be BAs under HIPAA (Advanced Care Hospitalists, Pagosa Springs, and Cottage Health)ย ย 
    • 1 CE experienced an email phishing cyber-attack (Anthem, Inc.)ย 
    • 4 CEs made PHI or patient privacy vulnerable by exposing the same via TV shows, interviews, or recordings (Allergy Associates of Hartford, Boston Medical Center, Brigham and Womenโ€™s Hospital, and Massachusetts General Hospital)
    • 4 CEs lacked HIPAA-mandated risk assessment, risk analysis, risk notification, or risk management protocols (Cottage Health, MD Anderson, Advanced Care Hospitalists, and Fresenius Medical Care North America)

    From this analysis, it can be ascertained that CEs and BAs can avoid facing settlements and judgements due to violations of the HIPAA Privacy Rule and the HIPAA Security Rule by instituting the following โ€œgolden rulesโ€ and ensuring their staff are fully trained in the same:

    • Do have robust and comprehensive plan to assess, identify, report, respond, and manage all security or privacy risks.
    • Do ensure a signed and completed BAA is on file for all BAs
    • Do have highly specific protocols in place governing the collection, storage, transmission, and disposal of patient PHI and ePHI.

    Best practices include annual and periodic training for their workforce, conducting the required security risk assessment in an ongoing/periodic manner, and internally enforcing HIPAA policies and procedures to cover the organizationโ€™s security management processes.

    Organizations, large and small, must be aware of the aggressive posture of enforcement and record settlement amounts under OCR and this current administration. My advice for any organization is to conduct a thorough evaluation of the current HIPAA compliance in place. Make sure all the requirements are covered.ย  If a compliance program is not is place, consider outsourcing and let a consultant do the heavy lifting.ย Often times, a consultant can get the program in place much quicker than relying on the organizationโ€™s internal staff.

    This blog was previously posted February 12, 2019