HHS Reaches Settlement with Clinical Laboratory for Alleged Violations of HIPAA Security Rule
Time 2 Minute Read

On May 25, 2021, the Office for Civil Rights (“OCR”) of the U.S. Department of Health and Human Services (“HHS”) announced that it had reached a settlement with Peachstate Health Management, LLC (“Peachstate”) for violations of the HIPAA Security Rule. As part of this settlement, Peachstate (dba AEON Clinical Laboratories) agreed to pay OCR $25,000 and to implement a robust corrective action plan.

Peachstate, which is based in Georgia, provides diagnostic and laboratory-developed tests, including clinical and genetic testing services. In December 2017, OCR began a compliance review of Peachstate to determine the company’s compliance with the HIPAA Privacy and Security Rules. This review found that Peachstate engaged in systemic noncompliance with the HIPAA Security Rule, including failures to (1) conduct an enterprise-wide risk analysis; (2) implement risk management and audit controls; and (3) maintain documentation of HIPAA Security Rule policies and procedures.

As part of the corrective action program, which includes three years of monitoring, Peachstate agreed to a number of conditions, including (1) conducting an enterprise-wide risk analysis; (2) developing and implementing a risk management plan; (3) revising the company’s written policies and procedures to comply with federal standards; (4) distributing these policies and procedures to all members of the company's workforce; and (5) maintaining all documents and records related to compliance with the corrective action plan for six years.

According to Acting OCR Director Robinsue Frohboese, “Clinical laboratories, like other covered health care providers, must comply with the HIPAA Security Rule. The failure to implement basic Security Rule requirements makes HIPAA regulated entities attractive targets for malicious activity, and needlessly risks patients’ electronic health information[.]”

Read the Resolution Agreement.

You May Also Be Interested In

Time 2 Minute Read

The U.S. Department of Health and Human Services’ Office for Civil Rights recently announced a settlement with health care software company MMG Fusion to resolve the company’s alleged noncompliance with the HIPAA Privacy, Security and Breach Notification Rules.

Time 3 Minute Read

The Connecticut Attorney General recently issued a legal memorandum regarding the application of existing Connecticut laws, such as the Connecticut Data Privacy Act, to the use of artificial intelligence.

Time 3 Minute Read

On March 20, 2026, Oklahoma Governor Kevin Stitt signed SB 546 into law, enacting the Oklahoma Consumer Data Privacy Act, which will take effect on January 1, 2027.

Time 4 Minute Read

Recent changes to 42 CFR Part 2 mean many covered entities must update their HIPAA Notices of Privacy Practices by February 16, 2026.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page