These four cases are OCR resolutions, not HIPAA lawsuits
Each is a resolution agreement with HHS's Office for Civil Rights, not a court judgment: the organization paid and agreed to corrective action. OCR investigates complaints and can refer possible crimes to the Department of Justice, as HHS's HIPAA enforcement process explains, and a private lawsuit or a state claim over the same facts is a separate matter.
Replies to online reviews created the disclosures
HHS reported that the California dental practice disclosed patient protected health information in responses to online reviews, along with other potential Privacy Rule violations. The practice agreed to a corrective action plan.
HHS reported a complaint alleging disclosure of patient PHI in a response to a negative review. HHS also identified a potential failure to implement policies and procedures concerning PHI.
In the two most recent HIPAA violation cases here, the disclosures HHS described were in replies to reviews. A safe reply template is only part of the fix: the practice also needs someone who watches the reviews, limited access to patient records, a trained responder, and a private route for the complaint. The Google reviews for doctors workflow puts those together without using a public reply to argue the record.
One scheduling calendar exposed two broken controls
HHS said a former employee retained access to a web-based scheduling calendar after employment ended. The matter involved ePHI of 557 individuals. HHS also reported disclosure to the calendar vendor without a business associate agreement.
Termination must reach third-party systems
Removing an internal account is incomplete if the former user can still enter the scheduler, call platform, file store, or marketing tool.
Procurement must know what data the vendor receives
A contract inventory needs the person responsible for the system, the data it receives, the agreement, the user list, and the offboarding procedure.
Anthem settled over the same controls, with almost 79 million people exposed
Anthem agreed in 2018 to pay $16 million and take corrective action after cyberattacks exposed the ePHI of almost 79 million people. HHS described potential failures including enterprise-wide risk analysis, review of information system activity, response to detected or suspected incidents, and access controls.
A small practice runs the same checks at its own scale: know where its patient data sits, find the threats and weak points, reduce them to a reasonable level, watch who accesses what, respond to incidents, and repeat the analysis when systems change.
What to check in your own practice
Read as HIPAA violation case studies, the four make one checklist: each question below comes from an example of a HIPAA violation HHS described in them.
- Who can reply on your public profiles, what facts can they see, and where do complaints go?
- When someone leaves, which external systems retain their separate accounts, tokens, or shared credentials?
- What information does each vendor receive in the real configuration, and what agreement covers that role?
- When did the inventory last change, and did the risk analysis change with it?
The HIPAA-compliant medical marketing guide applies the same checks to forms, tracking tags and testimonials, and the practice's privacy officer or counsel decides the legal treatment of its own facts.