惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

The Register - Security
The Register - Security
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
MyScale Blog
MyScale Blog
V
Visual Studio Blog
云风的 BLOG
云风的 BLOG
aimingoo的专栏
aimingoo的专栏
C
Check Point Blog
J
Java Code Geeks
大猫的无限游戏
大猫的无限游戏
L
LangChain Blog
Vercel News
Vercel News
阮一峰的网络日志
阮一峰的网络日志
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
S
Security @ Cisco Blogs
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
人人都是产品经理
人人都是产品经理
H
Hacker News: Front Page
L
Lohrmann on Cybersecurity
T
Troy Hunt's Blog
T
Threat Research - Cisco Blogs
A
About on SuperTechFans
T
Threatpost
AWS News Blog
AWS News Blog
Recent Commits to openclaw:main
Recent Commits to openclaw:main
T
Tor Project blog
Google Online Security Blog
Google Online Security Blog
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
T
Tenable Blog
W
WeLiveSecurity
博客园 - 叶小钗
K
Kaspersky official blog
Y
Y Combinator Blog
T
The Blog of Author Tim Ferriss
Hugging Face - Blog
Hugging Face - Blog
M
MIT News - Artificial intelligence
Hacker News - Newest:
Hacker News - Newest: "LLM"
Engineering at Meta
Engineering at Meta
有赞技术团队
有赞技术团队
D
Darknet – Hacking Tools, Hacker News & Cyber Security
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
S
Secure Thoughts
小众软件
小众软件
D
Docker
爱范儿
爱范儿
C
Cyber Attacks, Cyber Crime and Cyber Security
N
News and Events Feed by Topic
S
Schneier on Security
博客园 - 三生石上(FineUI控件)
D
DataBreaches.Net

WhatIs

Hims & Hers launches AI agent for lab results Twilio revamps, updates customer engagement platform CISA launches critical infrastructure cyber resilience initiative Most patients find appointment scheduling, billing overly complex Teradata's latest targets putting agentic AI into production AHA, Joint Commission launch cyber resilience program Tableau in transition as AI forces BI vendors to evolve California hospitals sue Elevance over out-of-network penalty CMS Health Tech Ecosystem adds electronic prior auth pledge Atlassian MCP updates take aim at AI token usage Leapfrog: Hospitals improved in 17 patient safety measures United promises another 30% cut to prior auths in 2026 AI outperforms docs on clinical reasoning, but not ready for solo work ServiceNow's Autonomous CRM takes aim at Salesforce ServiceNow reintroduces itself as an AI 'security company' New Tableau leader talks vendor's evolution in era of AI Deloitte warns of a "bubble effect" caused by the GLP-1 boom Tableau repositions for AI, unveils new knowledge layer IBM Bob AI coding agent ships, HashiCorp AIOps previewed DOJ forms West Coast Strike Force to stop healthcare fraud Most people benefit from the ACA's free preventive services SAP acquisitions of Dremio, Prior Labs target AI development Bridging the gap: Legacy tools gain enterprise AI support Amazon Connect Talent: AWS enters AI interviewing market AHA, West Health launch health tech adoption initiative How are states preparing for Medicaid work requirements? Medical device security improves, but cyberattacks remain pervasive Weekly news roundup: Musk vs. Altman, Google’s Pentagon AI deal, China and EU hit Meta Skin substitute spending driven by patients, products, prices Clinical AI company Aidoc snags $150M in new funding Qlik's Capone departs after eight years as CEO OIG: CMS paid millions in improper virtual care payments FDA moves toward real-time review of clinical trial data FQHCs in low-income neighborhoods have lower cancer screening rates Solving quantum computing's longstanding no-cloning problem Qdrant boosts performance, reliability to meet AI needs Racial health disparities still impact U.S. as policy changes loom Agentforce Operations tackles workflow orchestration Boehringer's dual agonist obesity drug spurs up to 16.6% weight loss Legacy architecture, awareness gaps stifle microsegmentation adoption in healthcare AMA alerts officials of health plans' No Surprises Act abuse Latest SAS capabilities focus on fostering reliable AI AHA calls for TEFCA individual access SOP delay, citing patient privacy concerns Actian targets secure, compliant AI with new vector database Payers promise standardized electronic prior auths MIT EmTech: 2026 is the year AI goes to work As Claude Design debuts, Adobe users -- and buyers -- shrug GoodData joins agentic AI development mix with Agent Builder Comfort, affordability top drivers of digital mental health tool use CMS accelerates Medicare coverage for breakthrough medical devices Weekly news roundup: Tim Cook exits Apple, Meta layoffs intensify and Anthropic investigates Claude Merck inks $1 billion AI drug development deal with Google Cloud OpenAI launches ChatGPT for Clinicians 90% of patients re-check AI chatbot health info with other sources Gemini Enterprise Agent Platform adds 'connective tissue' to Vertex AI AMA urges greater oversight of AI mental health chatbots CMS benches BALANCE Model for Medicare Former ransomware negotiator pleads guilty to BlackCat conspiracy New Google TPUs multiply AI infrastructure efficiency When brand-name drugs need a prior auth, brace for delays Google unveils data cloud purpose built for agentic AI Snowflake updates further goal of being control pane for AI UnitedHealthcare eliminates prior authorization for rural providers Yelp launches appointment scheduling button from Zocdoc Oracle takes steps toward CMS Health Tech Ecosystem goals OpenAI debuts AI model GPT-Rosalind to speed up drug discovery Which patient care access barriers deter cancer screening? Redis unveils Feature Form to improve AI, ML workloads Adobe defines its AI-powered customer experience platform How to escape agentification pilot purgatory for scalable AI New HSCC guidance tackles third-party AI risk Data quality, fast failures and quick wins key to AI success Stop Overpaying for Storage: A FinOps Guide for CIOs AWS launches AI-driven tool to speed up early-stage antibody discovery AMA: Clinician burnout in specialties persists as overall rates drop Mental health parity remains elusive in 43 states Before revenue cycle AI, payers and providers need to get along Edge and physical AI poised to upend enterprise networks Salesforce releases Agentforce dev tools, updates Agent Fabric Cyberattack continues to disrupt operations at Signature Healthcare FDA reminds sponsors, researchers to report clinical trial results AI arms race leading to prior auth problems, reimbursement cuts Abridge dives deeper into clinical decision support with NEJM, AMA AI provider search is here. How can health orgs stay visible? Judge dismisses No Surprises Act lawsuit against HaloMD What IT leaders should know from Nutanix .NEXT HubSpot builds answer engine optimization into its platform Sutter Health, MemorialCare face class action lawsuit over AI scribe use Latest Qlik tools target helping users achieve AI goals CMS taps Verily, Noom, 150+ others to participate in ACCESS model Starburst intros AI assistant to boost analysis, exploration Payers face faster prior authorization approvals under CMS proposal Lenovo deploys AI data agent for marketing, UX, e-commerce Cisco Galileo buy reflects blurring lines in AI observability CMS proposes 2.4% IPPS bump, joint replacement model expansion Patients unsure what to trust amid health information overload Nutanix expands flexibility by building out external storage Amazon Pharmacy adds Lilly's obesity pill with same-day delivery ServiceNow AI pricing change takes on enterprise ROI struggles Oracle's Sudha Raghavan on AI's infrastructure renaissance
OCR settles four HIPAA investigations, prioritizes risk analysis
2026-04-24 · via WhatIs

Jill Hughes

By

Published: 23 Apr 2026

The HHS Office for Civil Rights announced four settlements with HIPAA-covered entities stemming from separate ransomware investigations it conducted under the HIPAA Security Rule.  

The incidents, though not related, collectively impacted more than 427,000 individuals and exposed unsecured protected health information. The affected entities paid OCR a total of $1.17 million, agreed to implement corrective action plans and consented to OCR monitoring for two years to resolve the investigations.  

All four incidents show that OCR continues to prioritize enforcing the risk analysis provisions of the HIPAA Security Rule, as it has since the first enforcement action under its risk analysis initiative was issued in October 2024.  

Notably, the four breaches were not particularly large, with the smallest impacting just 9,300 individuals. This shows that OCR is not only pursuing settlements with large health systems or entities that have experienced disproportionately large breaches. Rather, any HIPAA-covered entity that fails to implement the proper HIPAA-compliant safeguards to protect PHI could find itself the subject of an OCR investigation. 

The latest settlements mark 19 completed OCR investigations pertaining to ransomware incidents and 13 completed under OCR's risk analysis initiative. 

“Hacking and ransomware are the most frequent type of large breach reported to OCR," OCR Director Paula M. Stannard said in the announcement.  

"Proactively implementing the HIPAA Security Rule before a breach or an OCR investigation not only is the law but also is a regulated entity's best opportunity to prevent or mitigate the harmful effects of a successful cyberattack." 

OCR recommended that all HIPAA-covered entities take proactive steps to mitigate cyberthreats, including identifying where electronic PHI is located within the organization, implementing a risk management plan and incorporating lessons learned from cybersecurity incidents into the organization's overall security strategy.  

Here are the four settlements: 

Assured Imaging 

Assured Imaging, a medical imaging and screening service provider with corporate locations in Arizona and California, suffered a ransomware attack in May 2020 at the hands of PYSA ransomware cybercriminals.  

According to the settlement agreement, OCR launched an investigation into the incident and learned that PYSA had encrypted Assured's EMR system and potentially exfiltrated data, impacting 244,813 individuals. 

OCR's investigation revealed that Assured had never conducted a compliant risk analysis as required by HIPAA. What's more, the entity failed to notify the impacted individuals of the breach within 60 days of discovery.  

Assured did not admit liability. However, the entity agreed to pay HHS $375,000 to resolve the investigation. Assured also agreed to a corrective action plan that requires it to conduct a risk analysis, update and maintain policies to safeguard PHI and submit to training, among other measures. 

Regional Women's Health Group 

New Jersey-based Regional Women's Health Group (RWHG), now part of Axia Women's Health, paid OCR $320,000 and agreed to implement corrective actions stemming from a December 2020 data breach that impacted 37,000 patients.  

OCR's investigation revealed that "RWHG failed to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information that it holds," the settlement agreement stated. 

Like Assured, RWHG's corrective action plan requires it to conduct a risk analysis and improve its security posture over a two-year OCR monitoring period. 

Star Group, L.P. Health Benefits Plan 

Star Group, L.P. Health Benefits Plan, the self-funded employee benefits plan of a Connecticut-based energy provider, filed a breach report in October 2021 stating that it had experienced a ransomware attack. Approximately 9,300 individuals were affected. 

OCR found that SG Health Plan had impermissibly disclosed PHI and failed to conduct an accurate risk assessment to identify risks to PHI.  

SG Health Plan paid OCR $245,000 to resolve the investigation and entered into a corrective action plan. 

Consociate Health 

Consociate Health, a HIPAA business associate and third-party administrator of employee-sponsored benefit programs, fell victim to a phishing attack in July 2020. Six months after initial access, the cyberthreat actor deployed ransomware and gained access to a server containing the PHI of approximately 136,500 individuals. 

Again, OCR's investigation posited that Consociate had failed to conduct a thorough risk assessment of the vulnerabilities to the confidentiality of patients' PHI. HHS accepted a $225,000 payment from Consociate to resolve the investigation, along with a corrective action plan.  

Jill Hughes has covered health tech news since 2021.

Dig Deeper on HIPAA compliance and regulation