HIPAA Settlement News: Record Fines and Right of Access Cases

Federal regulators have announced more than 20 HIPAA settlements and civil monetary penalties across 2025 and 2026, with the U.S. Department of Health and Human Services Office for Civil Rights (OCR) targeting hospitals, business associates, retailers, accounting firms, dental software vendors, and employer-sponsored health plans. Nearly every case shares the same underlying finding: the organization never conducted a proper risk analysis of its electronic protected health information before a breach hit. Dollar amounts have ranged from $10,000 to $3 million, and every settlement carries years of federal oversight on top of the check.

Recent HIPAA Settlements in 2025

The largest 2025 settlement came early. On January 14, OCR announced a $3 million agreement with Solara Medical Supplies over a phishing attack that compromised more than 114,000 patient records between April and June 2019. Solara then mailed breach notification letters to the wrong addresses, exposing another 1,531 people. OCR cited an inadequate risk analysis, insufficient security measures, and late breach notifications.1HHS.gov. Solara Medical Supplies Resolution Agreement and Corrective Action Plan

On February 20, 2025, OCR imposed a $1.5 million civil monetary penalty on Warby Parker after credential-stuffing attacks between September and November 2018 exposed names, addresses, payment card data, and prescription information for nearly 198,000 customers. OCR found three Security Rule violations, including failure to conduct a risk analysis and failure to review system activity logs. Warby Parker did not contest the penalty and waived its right to a hearing. Because corrective action plans are only part of negotiated settlements rather than imposed penalties, OCR could not require one here.2HHS.gov. Penalty Against Warby Parker3HIPAA Journal. Warby Parker HIPAA Penalty

USR Holdings, a business associate managing mental health and substance abuse treatment facilities, paid $337,750 in a settlement announced January 8, 2025. Between August and December 2018, unauthorized parties accessed and deleted electronic health records affecting 2,903 individuals. The breach went undetected for nearly four months. OCR cited failures in risk analysis, system activity monitoring, and data backup procedures.4HHS.gov. USR Holdings Resolution Agreement and Corrective Action Plan

In March 2025, Health Fitness Corporation settled for $227,816 after a software misconfiguration left patient data exposed to internet search crawlers beginning in 2015. The company did not discover the problem until 2018 and did not complete a compliant risk analysis until January 2024, nearly six years after reporting the breach.5HHS.gov. OCR Settles HIPAA Security Rule Investigation With Health Fitness Corporation

Several settlements followed through the spring and summer.

  • BayCare Health System paid $800,000 in May 2025 after a former staff member’s credentials were used to access a patient’s records at a Florida hospital. The patient learned of the breach when an unknown person contacted her with photographs of her medical records. OCR found failures in access authorization, risk management, and audit controls.6HHS.gov. OCR HIPAA Agreement With BayCare
  • Comstar, LLC settled for $75,000 in June 2025 over a 2022 ransomware attack affecting roughly 585,000 individuals. OCR found the ambulance billing company had not performed a thorough risk analysis or implemented adequate risk management measures.7Nixon Peabody. 2025 HIPAA Enforcement Tally Rises Following Three New Settlements
  • Syracuse ASC agreed to $250,000 in July 2025 after the PYSA ransomware variant hit the ambulatory surgery center in March 2021, compromising names, Social Security numbers, financial data, and clinical information for 24,891 people. OCR also cited delayed breach notifications.8HHS.gov. OCR HIPAA Resolution Agreement With Syracuse ASC
  • BST & Co. CPAs, LLP settled for $175,000 in August 2025. The accounting firm, acting as a business associate, was hit by ransomware introduced through a phishing email in December 2019, exposing health information for 170,000 individuals from a New York physician group client.9HHS.gov. OCR Settles HIPAA Security Rule Investigation With BST

2026 Settlements

On February 19, 2026, Top of the World Ranch Treatment Center agreed to pay $103,000 following a March 2023 phishing attack that compromised records of 1,980 patients. The core finding, again, was that the organization had never conducted a compliant risk analysis. The agreement includes a two-year corrective action plan.10HHS.gov. OCR Settles HIPAA Security Rule Investigation With TWRTC

The largest 2026 case by breach size involved MMG Fusion, a dental software vendor whose systems were infiltrated in December 2020. Names, phone numbers, addresses, dates of birth, and appointment details for approximately 15 million individuals were stolen and later posted on the dark web. MMG did not report the breach. OCR only learned of it after receiving a complaint in January 2023. The investigation identified three failures: no risk analysis, no breach notification within the required 60 days, and impermissible disclosure of protected health information. The settlement, announced March 5, 2026, was just $10,000, a figure OCR said reflected the company’s financial condition. HIQOR Dental signed as MMG’s successor. The three-year corrective action plan is unusually extensive, requiring a full risk analysis, rewritten HIPAA policies, workforce training, and retroactive breach notifications to affected dental practices and their patients.11HHS.gov. OCR MMG Fusion HIPAA Agreement12HIPAA Journal. MMG Fusion HIPAA Settlement

In April 2026, OCR announced a $245,000 settlement with Star Group, L.P. Health Benefits Plan, a self-funded employer-sponsored group health plan. A 2021 ransomware attack had compromised records of 9,316 plan participants, including Social Security numbers, claims data, and benefits information. Employer health plans have historically attracted less enforcement attention than hospitals and insurers, and OCR found that the plan had failed to identify where its electronic health data was stored and had no documented risk analysis process at all.13HHS.gov. Resolution Agreements and Civil Money Penalties

The Common Thread Regulators Keep Citing

Every one of the first ten enforcement actions of 2025 cited the organization’s failure to conduct a thorough, enterprise-wide risk analysis as required by the HIPAA Security Rule. OCR has formalized this focus as a “Risk Analysis Initiative” and treats it as the foundation from which other security obligations follow. The agency has pursued penalties regardless of whether the underlying breach involved ransomware, phishing, misconfigured servers, or insider access.13HHS.gov. Resolution Agreements and Civil Money Penalties

Amounts vary widely because OCR weighs the nature of the violation, the number of people affected, the organization’s compliance history, and its financial condition. That is how functionally similar violations produced settlements from $10,000 for the financially distressed MMG Fusion up to $3 million for Solara.14HHS.gov. Enforcement Highlights

State Attorneys General Are Adding Parallel Penalties

OCR is not the only regulator pursuing HIPAA-related violations. State attorneys general have authority under the HITECH Act to bring civil actions, and they have been increasingly willing to do so, often coordinating across state lines.

In 2024, state AGs imposed roughly $19.5 million in fines across nine actions. California hit Blackbaud with a $6.75 million penalty over a ransomware breach affecting 5.5 million records. New York fined Enzo Biochem $4.5 million in a multistate action with New Jersey and Connecticut, and imposed $1 million on Albany ENT & Allergy Services, which was also required to invest $2.24 million in cybersecurity improvements.15HIPAA Journal. HIPAA Enforcement by State Attorneys General

Comstar, which paid OCR $75,000 in 2025, was also hit with a separate $515,000 state-level settlement with the Massachusetts attorney general, assisted by Connecticut, for the same breach. A single data breach can now trigger investigations from OCR, one or more state AGs, and private litigation at the same time.15HIPAA Journal. HIPAA Enforcement by State Attorneys General

The Largest HIPAA Settlements on Record

The current wave fits inside a longer arc of rising penalties. The biggest HIPAA settlements to date include:

Through October 2024, OCR had resolved 152 cases through civil monetary penalties or settlements, totaling nearly $145 million.14HHS.gov. Enforcement Highlights

Right of Access and Parental Access Cases

OCR’s other long-running enforcement priority, the Right of Access Initiative, targets organizations that fail to give patients timely access to their own health records. HIPAA requires covered entities to fulfill access requests within 30 days, and OCR has completed more than 50 enforcement actions under the initiative.13HHS.gov. Resolution Agreements and Civil Money Penalties

Oregon Health & Science University was assessed a $200,000 penalty in March 2025 for failing to provide timely access. Concentra, the occupational health company, settled for $112,500 in May 2025 after a patient made six access requests beginning in February 2018 and did not receive her records until March 2019. OCR had originally proposed a $250,000 penalty. The reduced amount was agreed to before a scheduled administrative hearing.20HHS.gov. OCR Settles With Concentra

In late 2025, OCR expanded the initiative to include parental access to minor children’s records as a specific enforcement priority. In a December 2025 guidance letter, OCR Director Paula Stannard warned that some health systems and electronic health record vendors have implemented age-based or policy-based restrictions that block parents from accessing their children’s records even when the parents are legally authorized. OCR has launched compliance reviews of large health systems and signaled that more investigations and settlements on parental access should be expected throughout 2026.21HHS.gov. OCR Letter on HIPAA Privacy Rule and Parental Access to Minor Children’s Medical Records

What a HIPAA Settlement Actually Requires

The dollar figure is only part of the obligation. Every recent settlement includes a corrective action plan that imposes years of federal oversight. Standard terms require the organization to conduct a comprehensive, enterprise-wide risk analysis; develop a written risk management plan with timelines and assigned responsibilities; rewrite and distribute HIPAA policies and procedures; train all workforce members who handle protected health information; and submit regular compliance reports to OCR, including documentation of any internal policy failures. Most plans run two years. Some extend to three. Organizations must keep compliance records for six years, and if they fall short on the plan, OCR can add further civil monetary penalties.22HHS.gov. L.A. Care Health Plan Resolution Agreement23HHS.gov. Health Specialists Resolution Agreement and Corrective Action Plan