Virginia State Bar
DC Bar
FairFax Bar Association

The $140,000 HIPAA Lesson: Why Every Covered Entity Needs a Compliance Program

Seddiq Law Firm PLLC

On October 8, 2026, the U.S. Department of Health and Human Services Office for Civil Rights announced its settlement with Shen Smiles, a small Pennsylvania dental practice.

The case is a useful reminder for HIPAA-covered healthcare providers, including many medical, dental, and therapy practices, and other covered healthcare providers. HIPAA compliance is not limited to preventing hackers from entering an electronic medical record system. It requires an operating compliance program.

One Patient Complaint Opened a Larger Investigation

The matter began when a former patient complained that Shen Smiles had not provided access to her health records despite multiple requests.

The practice told OCR that it could not provide the records because a former employee had taken them. OCR accepted the practice’s sworn statement that the requested records were no longer in its possession and did not pursue a violation of the patient’s right to access them. But that did not end the investigation. OCR asked the practice to produce its HIPAA policies and procedures. The practice responded that it had none.

According to OCR’s Notice of Proposed Determination, patient records were kept in unsecured locations, transported between offices and the dentist’s home, and regularly missing. Employees had not received formal HIPAA Privacy Rule training. When the practice believed a former employee had taken patient records, it did not discipline the employee or take other action to stop the conduct.

One patient’s records request exposed a much larger problem: the practice did not have a functioning HIPAA compliance program.

No Harm Was Not a Defense

Shen Smiles argued that the matter involved only one patient and that no physical, financial, or reputational harm had been established. It also argued that it had not previously been the subject of an OCR complaint or investigation. OCR acknowledged that it had not found evidence of actual harm. But the absence of harm was fortunate, not evidence that the practice had complied with HIPAA. The absence of a prior investigation also did not establish compliance. It simply meant that OCR had not examined the practice before.

HIPAA does not require OCR to wait until a patient suffers financial loss, reputational harm, or an interruption in care. A covered entity may violate HIPAA by failing to maintain required policies and safeguards even when no one proves that the failure caused harm.

The Two Violations Cost $1.4 Million Before Reduction

OCR identified two continuing violations. First, the practice had not implemented policies and procedures designed to comply with the HIPAA Privacy and Breach Notification Rules, as required by  45 C.F.R. § 164.530(i)(1). Second, the practice had not reasonably safeguarded protected health information from improper uses or disclosures, as required by 45 C.F.R. § 164.530(c)(2)(i).

OCR treated these as longstanding violations that had continued for approximately six years. It calculated a maximum potential penalty of $700,000 for each violation, for a total of $1.4 million. Because Shen Smiles was a small dental practice with ten employees serving a rural community, OCR reduced the amount by 90 percent. The resulting penalty was still $140,000. www.hhs.gov. Small size affected the amount of the penalty. It did not excuse the violations.

HIPAA Is More Than Hacking

HIPAA generally applies to health plans, healthcare clearinghouses, and healthcare providers that transmit health information electronically in connection with standardized transactions, such as submitting insurance claims directly or through a billing company. For covered entities, HIPAA includes the Privacy Rule, the Security Rule, and the Breach Notification Rule.

A hacking incident may implicate HIPAA. But so may an unanswered records request, unsecured paper files, inadequate employee training, missing policies, improper access, or a failure to investigate suspected misconduct.

In advising healthcare practices, we frequently encounter the assumption that using a reputable electronic medical record or electronic health record system transfers HIPAA responsibility to the software company.

It does not. An EHR or EMR vendor may provide encryption, audit logs, access controls, and backups. If the vendor is a business associate, it also has its own HIPAA obligations. But the vendor does not determine which employees should have access, train the practice’s workforce, terminate former employees’ credentials, secure paper records, respond to patient requests, or investigate internal misconduct.

An EHR is an important tool. It is not a HIPAA compliance program for healthcare providers.

We also frequently see practices overlook employee training. HIPAA requires covered entities to train workforce members on the policies relevant to their responsibilities and to document that training. The Privacy Rule requires a designated Privacy Official, and the Security Rule requires an identified Security Official responsible for protecting electronic patient information. www.ecfr.gov

A small practice may assign both responsibilities to the same person. But someone must be responsible, and the required work must actually be performed.

What Healthcare Practices Should Do Now

A HIPAA-covered practice should be able to:

  • Produce written privacy, security, and breach-response policies that reflect its actual operations.
  • Identify its Privacy Official and Security Official.
  • Show that employees receive appropriate training and that the training is documented.
  • Demonstrate that it has conducted a security risk analysis and addressed identified risks.
  • Explain how patient-record requests, employee access, complaints, security incidents, and possible breaches are handled.
  • Confirm that appropriate business associate agreements are in place with EHR companies, billing companies, consultants, and other vendors handling protected health information.

A generic policy manual sitting unread in a drawer is not enough. Compliance must be documented, understood, and followed.

Do Not Wait for the First Complaint

The Shen Smiles matter did not begin with a major cyberattack. It began with one patient asking for her records. That request gave OCR a reason to look more closely. What it found was not simply a missing file. It found years without the policies, safeguards, training, and accountability HIPAA required.

If your organization cannot produce those materials today, the time to address the problem is before a patient complaint, employee incident, missing record, or government investigation brings it to light.

Seddiq Law Firm assists physicians, dentists, healthcare professionals, medical practices,  and healthcare organizations with HIPAA compliance, policies and procedures, workforce training, compliance reviews, business associate agreements, and healthcare operational planning in Virginia and Washington, D.C.

Call (703) 558-9311, email info@seddiqlawfirm.com, or click here to contact us to schedule a consultation.

Disclaimer: This article is for general informational purposes only and does not constitute legal, tax, or financial advice. Reading this article does not create an attorney-client relationship with Seddiq Law Firm. You should not act, or refrain from acting, based on this article without consulting an attorney or other qualified advisor regarding your specific situation.

Client Reviews

Esquire Shafeek Seddiq was professional, courteous, responsive, and accommodating throughout my experience with his practice. I had two real estate related legal matters...

Albert Gumabay

Couldn’t have asked for a better team than Mariam and Shafeek. Extremely professional, reliable, and supportive from start to finish. Highly recommend working with them!

Emre Ozkaya
May 2026

Shafeek and his team guided me through the tedious process of opening my own mobile IV infusion business as a registered nurse. His team was amazing, timely, and...

Sarah Raxsdale
June 2026

What do you expect fron your law firm? Knowledge? Comminicafion? Fast responce? Kindness? Fair Practice? Answers and Find a solution for your needs? He has it all. One of...

Tuncer Dagdelen
April 2026

We had a great experience with Shafeek back in 2022 regarding a landlord-tenant matter. He was not able to handle it at the time, but he was kind to point us to another...

MDieu
July 2026

I contacted Mr Shafeek to review my lease agreement to start a new venture in Virginia. He was so professional and proactive. I am glad that I took his professional...

Syed Mehdi
May 2026

Fill Out Our Contact Form