Call Us Today! 877-659-2467

Business Associate fined for a data breach UNDER 500 patient records

Business associate fined non compliant

Most of us are familiar with fines for data breaches of over 500 patient records. This time a business associate was fined $75K for 267 records.

Covered entities are responsibility to vet their business associates. This includes making sure they understand the HIPAA rules. Such as, conducting risk assessments, determining vulnerabilities and how to mitigate them, and maintaining proper HIPAA policies and procedures. While it is unusual to see a fine like this for under 500 records, this says the Office for Civil Rights (OCR) is now setting fines for breaches under 500 patient records. If this business associate had done their due diligence and had tried to be HIPAA compliant, I truly doubt they would have been fined. Compliance can be achieved in 7 Steps with our HIPAA Keeper™ System!

Do not be afraid to ask who conducted and when their last risk analysis was updated. Ask if you may see a copy of their data security policies. Ask for their HIPAA training certificates or a training list of employees who will be working with your practice.

iHealth Solutions, LLC (doing business as Advantum Health), a Kentucky-based business associate that provides coding, billing, and onsite information technology services to health care providers has paid $75,000 to OCR and has agreed to implement a corrective action plan.

Under the terms of the settlement agreement, iHealth Solutions will be monitored by OCR for two years to ensure compliance with the HIPAA Security Rule. iHealth Solutions has agreed to take the following steps:

  • Conduct an accurate and thorough analysis of its organization to determine the possible risks and vulnerabilities to the electronic protected health information it holds;
  • Develop and implement a risk management plan to address and mitigate identified security risks and vulnerabilities to the confidentiality, integrity, and availability of its electronic protected health information;
  • Implement a process to evaluate environmental and operational changes that affect the security of electronic protected health information; and
  • Develop, maintain, and revise, as necessary, its written HIPAA policies and procedures.

Sound familiar? YES, this is what covered entities are required to do! Business associates and their subcontractors (business associates of business associates) are required under HIPAA to follow the same rules and regulations as covered entities. Making sure you have a business associate agreement (BAA) in place is only the first step!

Let your business associates know Aris Medical Solutions has an online system called the HIPAA Keeper™, to help them get compliant and stay compliant with HIPAA!

Or to schedule a demo click the contact us tab and scroll down.

“Simplifying HIPAA through Automation, Education, and Support”

To read about other actual fines, click on our Education tab!

About Suze Shaffer

Suze Shaffer is the Owner and President of Aris Medical Solutions, a healthcare compliance company dedicated to simplifying HIPAA compliance. Through its online compliance solution, the HIPAA Keeper™, Aris Medical Solutions provides healthcare providers and business associates with the tools, documentation, training, and expert guidance needed to achieve and maintain HIPAA compliance.

Through the HIPAA Keeper™, Aris has assisted organizations nationwide with conducting risk analyses, developing risk management plans, implementing HIPAA Privacy and Security policies and procedures, and strengthening safeguards for protected health information. Aris Medical Solutions also considers applicable federal and state privacy and security requirements to help clients build a more comprehensive compliance program.

Suze is also a speaker and has presented at numerous conferences and professional events on HIPAA compliance, cybersecurity, risk management, and data breach prevention. Helping organizations understand their responsibilities and identify vulnerabilities before they result in a breach, audit, or investigation. She believes effective compliance begins with education. By helping organizations understand not only what they are required to do, but why those safeguards are important, organizations are better prepared to protect patient information and reduce their compliance risks.

At Aris Medical Solutions, the mission is simple: “Simplifying HIPAA” through education, expert guidance, and the HIPAA Keeper™, Aris Medical Solutions helps organizations turn complicated compliance requirements into a manageable, ongoing process.

The information provided reflects regulatory requirements and guidance available at the time of writing and is intended for educational purposes only. It should not be considered legal advice.

Share This HIPAA Blog

Could terminating an employee trigger an OCR investigation?

May 1, 2023

The OCR and FTC are investigating online tracking technologies

August 1, 2023
©2026 Aris Medical Solutions – HIPAA Risk Management | HIPAA Compliance Consultants | All Rights Reserved | Terms and Conditions | Privacy Policy
The content and images on this website is owned by Aris Medical Solutions and their owners. Do not copy any content or images without our consent.
Powered by Bandwise LLC