OCR Imposes $200,000 Penalty Against Oregon Health & Science University for HIPAA Right of Access Violations
Time 2 Minute Read

On March 6, 2025, the U.S. Department of Health and Human Services Office for Civil Rights (“OCR”) announced a $200,000 civil monetary penalty against Oregon Health & Science University (“OHSU”), a public academic health center and research university, for allegedly violating the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) Privacy Rule’s right of access provisions.

The HIPAA Privacy Rule requires covered entities to provide individuals or their personal representatives with access to their protected health information upon request within 30 days, with the possibility of one 30-day extension. In May 2020, OCR received a complaint regarding an individual who did not receive their requested records after their personal representative made an access request to OHSU on the individual’s behalf in April 2019. OCR resolved the complaint after notifying OHSU of its potential noncompliance with the Privacy Rule’s right of access provisions. OCR then initiated an investigation of OHSU based on a second complaint with respect to the same individual filed in January 2021.

Although OHSU provided part of the requested records in April 2019, OCR alleged that the university did not provide all of the requested records until August 2021. OCR’s investigation determined that OHSU failed to take timely action in response to the individual’s right of access requests, and subsequently imposed a $200,000 civil monetary penalty against OHSU.

You May Also Be Interested In

Time 4 Minute Read

Recent changes to 42 CFR Part 2 mean many covered entities must update their HIPAA Notices of Privacy Practices by February 16, 2026.

Time 2 Minute Read

On February 19, 2026, the U.S. Department of Health and Human Services’ Office for Civil Rights announced a $103,000 settlement with Top of the World Ranch Treatment Center, an Illinois substance use disorder treatment provider, to resolve alleged noncompliance with the HIPAA Security Rule’s risk analysis requirement.

Time 5 Minute Read

Perhaps the biggest EPR news to date is the February 6, 2026 decision by the US District Court for the District of Oregon granting the National Association of Wholesaler-Distributors Inc. (NAW) a preliminary injunction to block enforcement of Oregon’s Plastic Pollution and Recycling Modernization Act (RMA) pending a decision on the merits.[1] The Oregon litigation has the potential to affect the scope of EPR programs across the country, potentially extending beyond packaging to other products. In the meantime, product manufacturers and retailers must continue to wrestle with how best to manage EPR compliance and related costs and business impacts.

Time 2 Minute Read

As Oregon celebrated Data Privacy Day on January 28, Oregon Attorney General Dan Rayfield spotlighted a major advance in consumer data protection in the state: the Universal Opt-Out tool, now available to all Oregon residents under the Oregon Consumer Privacy Act.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page