<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:wfw="http://wellformedweb.org/CommentAPI/"
     xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
     xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
     xmlns:georss="http://www.georss.org/georss"
     xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#"
     xmlns:media="http://search.yahoo.com/mrss/">
    <channel>
        <title><![CDATA[HIPAA Security - Seddiq Law Firm PLLC]]></title>
        <atom:link href="https://www.seddiqlawfirm.com/blog/tags/hipaa-security/feed/" rel="self" type="application/rss+xml" />
        <link>https://www.seddiqlawfirm.com/blog/tags/hipaa-security/</link>
        <description><![CDATA[Seddiq Law Firm PLLC Website]]></description>
        <lastBuildDate>Fri, 09 Oct 2026 16:43:12 GMT</lastBuildDate>
        
        <language>en-us</language>
        
            <item>
                <title><![CDATA[The $140,000 HIPAA Lesson: Why Every Covered Entity Needs a Compliance Program]]></title>
                <link>https://www.seddiqlawfirm.com/blog/hipaa-compliance-140000-ocr-penalty/</link>
                <guid isPermaLink="true">https://www.seddiqlawfirm.com/blog/hipaa-compliance-140000-ocr-penalty/</guid>
                <dc:creator><![CDATA[Seddiq Law Firm PLLC]]></dc:creator>
                <pubDate>Fri, 09 Oct 2026 16:38:38 GMT</pubDate>
                
                    <category><![CDATA[Healthcare]]></category>
                
                
                    <category><![CDATA[Healthcare Compliance]]></category>
                
                    <category><![CDATA[Healthcare Privacy]]></category>
                
                    <category><![CDATA[HIPAA]]></category>
                
                    <category><![CDATA[HIPAA Security]]></category>
                
                    <category><![CDATA[Patient Privacy]]></category>
                
                
                
                    <media:thumbnail url="https://seddiqlawfirm-com.justia.site/wp-content/uploads/sites/1349/2026/10/SLF-HIPAA-Article.jpg" />
                
                <description><![CDATA[<p>A $140,000 OCR penalty shows why covered entities need more than an EHR. HIPAA requires policies, safeguards, training, and accountable officials.</p>
]]></description>
                <content:encoded><![CDATA[
<p class="wp-block-paragraph">On October 8, 2026, the U.S. Department of Health and Human Services Office for Civil Rights announced its <a href="https://www.hhs.gov/press-room/hhs-office-civil-rights-settles-hipaa-privacy-rule-investigation-shen-smiles.html">settlement with Shen Smiles</a>, a small Pennsylvania dental practice.</p>



<p class="wp-block-paragraph">The case is a useful reminder for HIPAA-covered healthcare providers, including many medical, dental, and therapy practices, and other covered healthcare providers. HIPAA compliance is not limited to preventing hackers from entering an electronic medical record system. It requires an operating compliance program.</p>



<h2 id="h-one-patient-complaint-opened-a-larger-investigation" class="wp-block-heading"><strong>One Patient Complaint Opened a Larger Investigation</strong></h2>



<p class="wp-block-paragraph">The matter began when a former patient complained that Shen Smiles had not provided access to her health records despite multiple requests.</p>



<p class="wp-block-paragraph">The practice told OCR that it could not provide the records because a former employee had taken them. OCR accepted the practice’s sworn statement that the requested records were no longer in its possession and did not pursue a violation of the patient’s right to access them. But that did not end the investigation. OCR asked the practice to produce its HIPAA policies and procedures. The practice responded that it had none.</p>



<p class="wp-block-paragraph">According to OCR’s <a href="https://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/agreements/npi-shen-smiles/index.html">Notice of Proposed Determination</a>, patient records were kept in unsecured locations, transported between offices and the dentist’s home, and regularly missing. Employees had not received formal HIPAA Privacy Rule training. When the practice believed a former employee had taken patient records, it did not discipline the employee or take other action to stop the conduct.</p>



<p class="wp-block-paragraph"><strong><em>One patient’s records request exposed a much larger problem: the practice did not have a functioning HIPAA compliance program.</em></strong></p>



<h2 id="h-no-harm-was-not-a-defense" class="wp-block-heading"><strong>No Harm Was Not a Defense</strong></h2>



<p class="wp-block-paragraph">Shen Smiles argued that the matter involved only one patient and that no physical, financial, or reputational harm had been established. It also argued that it had not previously been the subject of an OCR complaint or investigation. OCR acknowledged that it had not found evidence of actual harm. But the absence of harm was fortunate, not evidence that the practice had complied with HIPAA. The absence of a prior investigation also did not establish compliance. It simply meant that OCR had not examined the practice before.</p>



<p class="wp-block-paragraph">HIPAA does not require OCR to wait until a patient suffers financial loss, reputational harm, or an interruption in care. A covered entity may violate HIPAA by failing to maintain required policies and safeguards even when no one proves that the failure caused harm.</p>



<h2 id="h-the-two-violations-cost-1-4-million-before-reduction" class="wp-block-heading"><strong>The Two Violations Cost $1.4 Million Before Reduction</strong></h2>



<p class="wp-block-paragraph">OCR identified two continuing violations. First, the practice had not implemented policies and procedures designed to comply with the HIPAA Privacy and Breach Notification Rules, as required by &nbsp;<a href="https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.530">45 C.F.R. § 164.530(i)(1)</a>. Second, the practice had not reasonably safeguarded protected health information from improper uses or disclosures, as required by <a href="https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.530">45 C.F.R. § 164.530(c)(2)(i)</a>.</p>



<p class="wp-block-paragraph">OCR treated these as longstanding violations that had continued for approximately six years. It calculated a maximum potential penalty of $700,000 for each violation, for a total of $1.4 million. Because Shen Smiles was a small dental practice with ten employees serving a rural community, OCR reduced the amount by 90 percent. The resulting penalty was still $140,000. <a href="https://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/agreements/npi-shen-smiles/index.html">www.hhs.gov</a>. Small size affected the amount of the penalty. It did not excuse the violations.</p>



<h2 id="h-hipaa-is-more-than-hacking" class="wp-block-heading"><strong>HIPAA Is More Than Hacking</strong></h2>



<p class="wp-block-paragraph">HIPAA generally applies to health plans, healthcare clearinghouses, and healthcare providers that transmit health information electronically in connection with standardized transactions, such as submitting insurance claims directly or through a billing company. For covered entities, HIPAA includes the <a href="https://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/agreements/npi-shen-smiles/index.html">Privacy Rule</a>, the <a href="https://www.hhs.gov/hipaa/for-professionals/security/laws-regulations/index.html">Security Rule</a>, and the <a href="https://www.hhs.gov/hipaa/for-professionals/breach-notification/index.html">Breach Notification Rule</a>.</p>



<p class="wp-block-paragraph">A hacking incident may implicate HIPAA. But so may an unanswered records request, unsecured paper files, inadequate employee training, missing policies, improper access, or a failure to investigate suspected misconduct.</p>



<p class="wp-block-paragraph">In advising healthcare practices, we frequently encounter the assumption that using a reputable electronic medical record or electronic health record system transfers HIPAA responsibility to the software company.</p>



<p class="wp-block-paragraph">It does not. An EHR or EMR vendor may provide encryption, audit logs, access controls, and backups. If the vendor is a business associate, it also has its own HIPAA obligations. But the vendor does not determine which employees should have access, train the practice’s workforce, terminate former employees’ credentials, secure paper records, respond to patient requests, or investigate internal misconduct.</p>



<p class="wp-block-paragraph">An EHR is an important tool. It is not a HIPAA compliance program for healthcare providers.</p>



<p class="wp-block-paragraph">We also frequently see practices overlook employee training. HIPAA requires covered entities to train workforce members on the policies relevant to their responsibilities and to document that training. The Privacy Rule requires a designated Privacy Official, and the Security Rule requires an identified Security Official responsible for protecting electronic patient information. <a href="https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.530">www.ecfr.gov</a></p>



<p class="wp-block-paragraph">A small practice may assign both responsibilities to the same person. But someone must be responsible, and the required work must actually be performed.</p>



<h2 id="h-what-healthcare-practices-should-do-now" class="wp-block-heading"><strong>What Healthcare Practices Should Do Now</strong></h2>



<p class="wp-block-paragraph">A HIPAA-covered practice should be able to:</p>



<ul class="wp-block-list">
<li>Produce written privacy, security, and breach-response policies that reflect its actual operations.</li>



<li>Identify its Privacy Official and Security Official.</li>



<li>Show that employees receive appropriate training and that the training is documented.</li>



<li>Demonstrate that it has conducted a security risk analysis and addressed identified risks.</li>



<li>Explain how patient-record requests, employee access, complaints, security incidents, and possible breaches are handled.</li>



<li>Confirm that appropriate business associate agreements are in place with EHR companies, billing companies, consultants, and other vendors handling protected health information.</li>
</ul>



<p class="wp-block-paragraph">A generic policy manual sitting unread in a drawer is not enough. Compliance must be documented, understood, and followed.</p>



<h2 id="h-do-not-wait-for-the-first-complaint" class="wp-block-heading"><strong>Do Not Wait for the First Complaint</strong></h2>



<p class="wp-block-paragraph">The Shen Smiles matter did not begin with a major cyberattack. It began with one patient asking for her records. That request gave OCR a reason to look more closely. What it found was not simply a missing file. It found years without the policies, safeguards, training, and accountability HIPAA required.</p>



<p class="wp-block-paragraph">If your organization cannot produce those materials today, the time to address the problem is before a patient complaint, employee incident, missing record, or government investigation brings it to light.</p>



<p class="wp-block-paragraph">Seddiq Law Firm assists physicians, dentists, healthcare professionals, medical practices, &nbsp;and healthcare organizations with <a href="https://www.seddiqlawfirm.com/practice-areas/healthcare-compliance/?utm_source=chatgpt.com">HIPAA compliance</a>, policies and procedures, workforce training, compliance reviews, business associate agreements, and healthcare operational planning in Virginia and Washington, D.C.</p>



<p class="wp-block-paragraph">Call (703) 558-9311, email <a href="mailto:info@seddiqlawfirm.com">info@seddiqlawfirm.com</a>, or <a href="https://www.seddiqlawfirm.com/contact-us/">click here to contact us</a> to schedule a consultation.</p>



<p class="wp-block-paragraph"><strong>Disclaimer:</strong> This article is for general informational purposes only and does not constitute legal, tax, or financial advice. Reading this article does not create an attorney-client relationship with Seddiq Law Firm. You should not act, or refrain from acting, based on this article without consulting an attorney or other qualified advisor regarding your specific situation.</p>



<p class="wp-block-paragraph"></p>
]]></content:encoded>
            </item>
        
    </channel>
</rss>