OCR’s Second Settlement Under HIPAA Right of Access Initiative
Time 2 Minute Read

On December 12, 2019, the U.S. Department of Health and Human Services’ (“HHS”) Office for Civil Rights (“OCR”) announced its second enforcement action and settlement under its HIPAA Right of Access Initiative. Under the terms of the settlement, Korunda Medical, LLC, agreed to pay $85,000 to settle a potential violation of HIPAA’s right of access.

According to HHS, “Korunda is a Florida-based company that provides comprehensive primary care and interventional pain management to approximately 2,000 patients annually.” In March 2019, OCR received a complaint that “Korunda [had] failed to forward a patient’s medical records in electronic format to a third party” after multiple requests by the patient. Based on the complaint, OCR provided Korunda with assistance on how to correct the issues and closed the complaint. Despite OCR’s assistance, Korunda continued to fail to provide the requested records, which resulted in another complaint to OCR. In May 2019, after OCR’s second intervention, Korunda provided the requested records, free-of-charge and in the requested format.

A news release quoted OCR Director, Roger Severino: “For too long, healthcare providers have slow-walked their duty to provide patients their medical records out of a sleepy bureaucratic inertia. We hope our shift to the imposition of corrective actions and settlements under our Right of Access Initiative will finally wake up healthcare providers to their obligations under the law.”

The HIPAA Rules generally require covered health care providers to provide medical records within 30 days of the access request in a readily producible format of the patient’s choosing, and they only permit providers to charge a reasonable cost-based fee. The OCR announced its Right of Access Initiative earlier this year, promising vigorous enforcement of HIPAA’s access rules. On September 9, 2019, OCR had announced its first enforcement action and settlement under this initiative against Bayfront Health St. Petersburg, which also settled for $85,000.

You May Also Be Interested In

Time 2 Minute Read

The U.S. Department of Health and Human Services’ Office for Civil Rights recently announced a settlement with health care software company MMG Fusion to resolve the company’s alleged noncompliance with the HIPAA Privacy, Security and Breach Notification Rules.

Time 4 Minute Read

Recent changes to 42 CFR Part 2 mean many covered entities must update their HIPAA Notices of Privacy Practices by February 16, 2026.

Time 2 Minute Read

On March 5, 2026, the California Privacy Protection Agency announced that the agency had reached a settlement with Ford Motor Company resolving an enforcement action against the company that alleged noncompliance with the California Consumer Privacy Act’s opt-out of sale/sharing rights.

Time 2 Minute Read

On February 19, 2026, the U.S. Department of Health and Human Services’ Office for Civil Rights announced a $103,000 settlement with Top of the World Ranch Treatment Center, an Illinois substance use disorder treatment provider, to resolve alleged noncompliance with the HIPAA Security Rule’s risk analysis requirement.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page