惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

罗磊的独立博客
The GitHub Blog
The GitHub Blog
Hugging Face - Blog
Hugging Face - Blog
博客园 - 聂微东
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
IT之家
IT之家
小众软件
小众软件
博客园_首页
G
Google Developers Blog
Apple Machine Learning Research
Apple Machine Learning Research
MyScale Blog
MyScale Blog
Engineering at Meta
Engineering at Meta
Jina AI
Jina AI
酷 壳 – CoolShell
酷 壳 – CoolShell
人人都是产品经理
人人都是产品经理
B
Blog RSS Feed
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
D
Docker
B
Blog
雷峰网
雷峰网
WordPress大学
WordPress大学
Stack Overflow Blog
Stack Overflow Blog
宝玉的分享
宝玉的分享

HHS’ Office for Civil Rights Settles HIPAA Investigation of Health Care Software Company

Delaware Expands State Privacy Law Privacy & Cybersecurity Law Blog Update HHS’ Office for Civil Rights Settles HIPAA Investigation of Health Care Software Company New Jersey Enacts New Restrictions on Health Care Facilities’ Use of Patient Data HHS Final Rule on 42 CFR Part 2 Requires Targeted Updates to HIPAA Privacy Notices
HHS OCR Settles HIPAA Security Rule Investigation with To...
2026-03-02 · via HHS’ Office for Civil Rights Settles HIPAA Investigation of Health Care Software Company

HHS OCR Settles HIPAA Security Rule Investigation with Top of the World Ranch Treatment Center for $103,000

On February 19, 2026, the U.S. Department of Health and Human Services’ Office for Civil Rights (“OCR”) announced a $103,000 settlement with Top of the World Ranch Treatment Center (“TWRTC”), an Illinois substance use disorder treatment provider, to resolve alleged noncompliance with the HIPAA Security Rule’s risk analysis requirement.

According to OCR’s announcement, the investigation stemmed from a March 2023 breach report filed by TWRTC following a phishing attack. An unauthorized third party accessed electronic protected health information (“ePHI”) through a workforce member’s email account, compromising the ePHI of 1,980 patients.

OCR concluded that TWRTC failed to conduct an accurate and thorough risk analysis to assess potential risks and vulnerabilities to the confidentiality, integrity, and availability of its ePHI, as required by the HIPAA Security Rule.

In announcing the settlement, OCR Director Paula M. Stannard emphasized the importance of compliance with the Risk Analysis provision, particularly as regulated entities face increasing cybersecurity threats.

Settlement Terms and Corrective Action Plan

Under the resolution agreement, TWRTC agreed to:

  • conduct and complete an accurate and thorough risk analysis;
  • develop and implement a risk management plan to address identified risks and vulnerabilities;
  • develop, maintain and revise written policies and procedures to comply with the HIPAA Privacy, Security and Breach Notification Rules; and
  • provide annual HIPAA training to workforce members with access to ePHI.

OCR’s Risk Analysis Initiative

OCR identified this matter as its 11th enforcement action under its Risk Analysis Initiative, which focuses on compliance with the Security Rule’s requirement that covered entities and business associates conduct an accurate and thorough assessment of risks and vulnerabilities to ePHI.

OCR also reiterated practical steps regulated entities should take to mitigate cyber threats, including:

  • identifying where ePHI resides and how it flows through systems;
  • periodically conducting and updating risk analyses;
  • implementing audit controls and regularly reviewing system activity;
  • authenticating users seeking access to ePHI;
  • encrypting ePHI in transit and at rest, where appropriate;
  • incorporating lessons learned from incidents into security management processes; and
  • providing role-based HIPAA training.

The investigation and settlement demonstrate OCR’s commitment to enforcing HIPAA requirements, particularly under the Security Rule.