| Matter | HHS-reported event | Control to examine |
|---|---|---|
| New Vision Dental, 2022 | $23,000 resolution concerning disclosure of patient PHI in responses to online reviews, plus other potential Privacy Rule violations | Public review-response boundary and staff escalation |
| Manasa Health Center, 2023 | $30,000 resolution after a complaint alleging PHI was disclosed in a response to a negative online review; HHS also cited policies and procedures | Written process, training, and approval for public responses |
| Pagosa Springs Medical Center, 2018 | $111,400 resolution involving a former employee's continued access to a web scheduling calendar and use of a vendor without the required written assurances | Access termination, vendor inventory, and business associate agreement |
| Anthem, 2018 | $16 million resolution after cyberattacks exposed ePHI of almost 79 million people; HHS described it at the time as a record settlement | Enterprise risk analysis, access and monitoring, and response to sustained attack |
New Vision Dental: the disclosure happened in the reply
HHS said New Vision Dental in California disclosed patient PHI while responding to online reviews. The practice paid $23,000 and agreed to a corrective action plan. The amount is not the general rule. The transferable fact is that a public reputation response can itself become the impermissible disclosure.
A patient can choose to publish their own account. The provider still controls what the provider publishes. A responder who confirms dates, treatment, account history, or even the relationship may add protected information the reviewer did not disclose or authorize the practice to disclose.
Operational change: give profile managers a privacy-safe response frame and a private escalation route. Do not let the person defending the practice improvise from the record.
Manasa Health Center: a template is insufficient without a process
HHS reported that Manasa Health Center resolved a complaint alleging PHI was disclosed in a response to a negative review. HHS identified potential violations involving both the disclosure and failure to implement policies and procedures concerning PHI. The center paid $30,000 and agreed to a corrective action plan.
The second point matters. Saving a neutral sentence in a document does not establish who monitors reviews, who may respond, which situations require no response, or when a matter moves to the privacy officer. The control is the whole operating sequence.
Operational change: name the owner, restrict profile access, train the responder, log the public URL and action, and route case-specific facts into approved systems.
Pagosa Springs: offboarding and vendor contracts meet in one calendar
HHS said a former employee retained access to Pagosa Springs Medical Center's web-based scheduling calendar after employment ended. The matter involved ePHI of 557 individuals. HHS also reported disclosure to the calendar vendor without a business associate agreement. The center paid $111,400 and agreed to a corrective action plan.
This is not principally a “strong password” story. One system had two governance failures: access was not removed when the relationship ended, and the vendor relationship did not have the required written assurance. A marketing or scheduling stack can accumulate the same gaps when nobody owns the vendor and user inventory.
Operational change: keep an inventory of systems, users, data, owner, agreement, and termination procedure. Offboarding is not complete until access to third-party systems is actually revoked.
Anthem: scale changes the consequence, not the need for a control
Anthem agreed in 2018 to pay $16 million and take corrective action after cyberattacks exposed the ePHI of almost 79 million people. HHS described it then as the largest health data breach and a record HIPAA settlement. The event is famous because of its scale. A small practice should resist drawing the useless conclusion that only national insurers have a meaningful security obligation.
The applicable lesson is proportional: know where ePHI exists, assess threats and vulnerabilities, reduce them, monitor access, and revisit the assessment when systems and conditions change. Buying a “HIPAA-ready” product does not perform the practice's risk analysis or configure the product.
Operational change: connect procurement, configuration, access, logging, incident response, and periodic review. The vendor's certificate cannot describe how the practice actually uses the system.
Use cases to test controls, not to frighten people into a package
A useful review takes each HHS-reported failure and asks whether the equivalent control exists in the current operation. Who can reply publicly? Which accounts survive staff departures? Which vendors receive patient information? When was the data-flow and risk analysis last updated? A “HIPAA website audit” that never reaches those systems is mostly inspecting the visible end of a much larger operation.
For marketing teams, begin with the concrete boundary in HIPAA-compliant medical marketing and the operable Google review workflow. Bring the resulting system map to the practice's privacy and legal owners for the actual determination.