惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

美团技术团队
罗磊的独立博客
SecWiki News
SecWiki News
The Register - Security
The Register - Security
The GitHub Blog
The GitHub Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
博客园 - 三生石上(FineUI控件)
S
Schneier on Security
IT之家
IT之家
博客园 - 聂微东
T
The Exploit Database - CXSecurity.com
Recorded Future
Recorded Future
大猫的无限游戏
大猫的无限游戏
Know Your Adversary
Know Your Adversary
Latest news
Latest news
Vercel News
Vercel News
G
GRAHAM CLULEY
D
DataBreaches.Net
D
Darknet – Hacking Tools, Hacker News & Cyber Security
S
SegmentFault 最新的问题
博客园_首页
雷峰网
雷峰网
T
Tenable Blog
Spread Privacy
Spread Privacy
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
酷 壳 – CoolShell
酷 壳 – CoolShell
Cisco Talos Blog
Cisco Talos Blog
V
Visual Studio Blog
J
Java Code Geeks
博客园 - Franky
The Cloudflare Blog
Apple Machine Learning Research
Apple Machine Learning Research
C
CERT Recently Published Vulnerability Notes
T
Threatpost
Google DeepMind News
Google DeepMind News
F
Fortinet All Blogs
P
Privacy International News Feed
T
Threat Research - Cisco Blogs
T
The Blog of Author Tim Ferriss
V
Vulnerabilities – Threatpost
Recent Announcements
Recent Announcements
Blog — PlanetScale
Blog — PlanetScale
Security Latest
Security Latest
U
Unit 42
M
MIT News - Artificial intelligence
Y
Y Combinator Blog
K
Kaspersky official blog
有赞技术团队
有赞技术团队
B
Blog
腾讯CDC

HHS’ Office for Civil Rights Settles HIPAA Investigation of Health Care Software Company

Privacy & Cybersecurity Law Blog Update HHS’ Office for Civil Rights Settles HIPAA Investigation of Health Care Software Company New Jersey Enacts New Restrictions on Health Care Facilities’ Use of Patient Data HHS Final Rule on 42 CFR Part 2 Requires Targeted Updates to HIPAA Privacy Notices
HHS OCR Settles HIPAA Security Rule Investigation with Top of the World Ranch Treatment Center for $103,000
2026-03-02 · via HHS’ Office for Civil Rights Settles HIPAA Investigation of Health Care Software Company

HHS OCR Settles HIPAA Security Rule Investigation with Top of the World Ranch Treatment Center for $103,000

On February 19, 2026, the U.S. Department of Health and Human Services’ Office for Civil Rights (“OCR”) announced a $103,000 settlement with Top of the World Ranch Treatment Center (“TWRTC”), an Illinois substance use disorder treatment provider, to resolve alleged noncompliance with the HIPAA Security Rule’s risk analysis requirement.

According to OCR’s announcement, the investigation stemmed from a March 2023 breach report filed by TWRTC following a phishing attack. An unauthorized third party accessed electronic protected health information (“ePHI”) through a workforce member’s email account, compromising the ePHI of 1,980 patients.

OCR concluded that TWRTC failed to conduct an accurate and thorough risk analysis to assess potential risks and vulnerabilities to the confidentiality, integrity, and availability of its ePHI, as required by the HIPAA Security Rule.

In announcing the settlement, OCR Director Paula M. Stannard emphasized the importance of compliance with the Risk Analysis provision, particularly as regulated entities face increasing cybersecurity threats.

Settlement Terms and Corrective Action Plan

Under the resolution agreement, TWRTC agreed to:

  • conduct and complete an accurate and thorough risk analysis;
  • develop and implement a risk management plan to address identified risks and vulnerabilities;
  • develop, maintain and revise written policies and procedures to comply with the HIPAA Privacy, Security and Breach Notification Rules; and
  • provide annual HIPAA training to workforce members with access to ePHI.

OCR’s Risk Analysis Initiative

OCR identified this matter as its 11th enforcement action under its Risk Analysis Initiative, which focuses on compliance with the Security Rule’s requirement that covered entities and business associates conduct an accurate and thorough assessment of risks and vulnerabilities to ePHI.

OCR also reiterated practical steps regulated entities should take to mitigate cyber threats, including:

  • identifying where ePHI resides and how it flows through systems;
  • periodically conducting and updating risk analyses;
  • implementing audit controls and regularly reviewing system activity;
  • authenticating users seeking access to ePHI;
  • encrypting ePHI in transit and at rest, where appropriate;
  • incorporating lessons learned from incidents into security management processes; and
  • providing role-based HIPAA training.

The investigation and settlement demonstrate OCR’s commitment to enforcing HIPAA requirements, particularly under the Security Rule.