HHS Imposes Civil Penalty Against Interstate Network of Medical Providers Following Ransomware Attack
Time 2 Minute Read

On October 3, 2024, the U.S. Department of Health and Human Services’ (“HHS”) Office for Civil Rights (“OCR”) announced a monetary penalty of $240,000 against Providence Medical Institute (“Providence”) stemming from violations of the Health Insurance Portability and Accountability Act (“HIPAA”) Security Rule in relation to a series of ransomware attacks against a California orthopedics practice acquired by Providence in 2016. Providence, an interstate network of medical providers headquartered in California and Washington, acquired the Center for Orthopaedic Specialists (“COS”) in July 2016 but did not integrate COS into Providence IT infrastructure until 2019. According to OCR, COS sustained a series of ransomware attacks in 2018, resulting in the compromise of 85,000 individuals’ electronic protected health information (“PHI”). Providence reported the breaches to OCR in April 2018.

OCR’s subsequent investigation into Providence revealed multiple cybersecurity and privacy issues, including “unsupported and obsolete” operating systems, improperly configured firewalls, and generic credential sharing among COS personnel. OCR ultimately found Providence was liable for two violations of the HIPAA Security Rule, including failure to put in place a business associate agreement and failure to implement necessary policies and procedures to limit electronic PHI access to only authorized persons or software programs. OCR initially issued a Notice of Proposed Determination in March 2024, seeking to impose a civil monetary penalty, which Providence did not contest. Accordingly, OCR issued a Notice of Final Determination to Providence in July 2024.

OCR, in its announcing the penalty, highlighted the significant rise in large ransomware incidents reported to OCR since 2018 (an increase of 264%), a point it has made in several press releases in recent months. OCR also stressed the importance of HIPAA-covered entities taking steps to prevent and mitigate cyber threats and provided a list of recommendations for doing so, including vendor diligence and risk management processes. This penalty marks the fifth OCR enforcement action relating to ransomware incidents.

You May Also Be Interested In

Time 2 Minute Read

The U.S. Department of Health and Human Services’ Office for Civil Rights recently announced a settlement with health care software company MMG Fusion to resolve the company’s alleged noncompliance with the HIPAA Privacy, Security and Breach Notification Rules.

Time 3 Minute Read

On March 24, 2026, Washington Governor Bob Ferguson signed House Bill 2225, an Act regulating artificial intelligence companion chatbots.

Time 2 Minute Read

California has introduced Assembly Bill 2244, proposing a pioneering “California Certified” labeling standard for foods not classified as ultra-processed. The bill relies on forthcoming regulatory definitions and imposes retail placement requirements for qualifying products. As California continues to advance UPF regulation, this initiative is expected to shape food law trends nationwide.

Time 1 Minute Read

As reported on the Hunton Employment & Labor Perspectives blog, SB 574 is a California bill that would set specific duties for attorneys who use generative artificial intelligence and would restrict how arbitrators may use such tools in decision-making.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page