惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

罗磊的独立博客
Y
Y Combinator Blog
Recent Announcements
Recent Announcements
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
V
Visual Studio Blog
MyScale Blog
MyScale Blog
M
MIT News - Artificial intelligence
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
T
The Blog of Author Tim Ferriss
Martin Fowler
Martin Fowler
博客园 - 【当耐特】
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
宝玉的分享
宝玉的分享
Engineering at Meta
Engineering at Meta
WordPress大学
WordPress大学
Google DeepMind News
Google DeepMind News
C
Check Point Blog
Last Week in AI
Last Week in AI
F
Fortinet All Blogs
博客园 - 聂微东
Blog — PlanetScale
Blog — PlanetScale
H
Help Net Security
GbyAI
GbyAI
云风的 BLOG
云风的 BLOG

South Dakota Enacts Genetic Data Privacy Act

HHS’ Office for Civil Rights Settles HIPAA Investigation of Health Care Software Company New Jersey Enacts New Restrictions on Health Care Facilities’ Use of Patient Data South Dakota Enacts Genetic Data Privacy Act New York Attorney General Reaches $500,000 Settlement with Orthopedics Practice Over 2023 Data Breach
HHS OCR Settles HIPAA Security Rule Investigation with To...
2026-03-02 · via South Dakota Enacts Genetic Data Privacy Act

HHS OCR Settles HIPAA Security Rule Investigation with Top of the World Ranch Treatment Center for $103,000

On February 19, 2026, the U.S. Department of Health and Human Services’ Office for Civil Rights (“OCR”) announced a $103,000 settlement with Top of the World Ranch Treatment Center (“TWRTC”), an Illinois substance use disorder treatment provider, to resolve alleged noncompliance with the HIPAA Security Rule’s risk analysis requirement.

According to OCR’s announcement, the investigation stemmed from a March 2023 breach report filed by TWRTC following a phishing attack. An unauthorized third party accessed electronic protected health information (“ePHI”) through a workforce member’s email account, compromising the ePHI of 1,980 patients.

OCR concluded that TWRTC failed to conduct an accurate and thorough risk analysis to assess potential risks and vulnerabilities to the confidentiality, integrity, and availability of its ePHI, as required by the HIPAA Security Rule.

In announcing the settlement, OCR Director Paula M. Stannard emphasized the importance of compliance with the Risk Analysis provision, particularly as regulated entities face increasing cybersecurity threats.

Settlement Terms and Corrective Action Plan

Under the resolution agreement, TWRTC agreed to:

  • conduct and complete an accurate and thorough risk analysis;
  • develop and implement a risk management plan to address identified risks and vulnerabilities;
  • develop, maintain and revise written policies and procedures to comply with the HIPAA Privacy, Security and Breach Notification Rules; and
  • provide annual HIPAA training to workforce members with access to ePHI.

OCR’s Risk Analysis Initiative

OCR identified this matter as its 11th enforcement action under its Risk Analysis Initiative, which focuses on compliance with the Security Rule’s requirement that covered entities and business associates conduct an accurate and thorough assessment of risks and vulnerabilities to ePHI.

OCR also reiterated practical steps regulated entities should take to mitigate cyber threats, including:

  • identifying where ePHI resides and how it flows through systems;
  • periodically conducting and updating risk analyses;
  • implementing audit controls and regularly reviewing system activity;
  • authenticating users seeking access to ePHI;
  • encrypting ePHI in transit and at rest, where appropriate;
  • incorporating lessons learned from incidents into security management processes; and
  • providing role-based HIPAA training.

The investigation and settlement demonstrate OCR’s commitment to enforcing HIPAA requirements, particularly under the Security Rule.