Close Menu
Global News HQ
    What's Hot

    High Yield, High Cost: The Real Returns Of ECC And SLR Investment (NYSE:ECC)

    December 16, 2025

    Client Challenge

    December 16, 2025

    MetaMask adds Bitcoin support after teasing it 10 months ago

    December 16, 2025
    Recent Posts
    • High Yield, High Cost: The Real Returns Of ECC And SLR Investment (NYSE:ECC)
    • Client Challenge
    • MetaMask adds Bitcoin support after teasing it 10 months ago
    • Morning meetings show managers are here to help, not hinder
    • Today's NYT Connections: Sports Edition Hints, Answers for Dec. 16 #449
    Facebook X (Twitter) Instagram YouTube TikTok
    Trending
    • High Yield, High Cost: The Real Returns Of ECC And SLR Investment (NYSE:ECC)
    • Client Challenge
    • MetaMask adds Bitcoin support after teasing it 10 months ago
    • Morning meetings show managers are here to help, not hinder
    • Today's NYT Connections: Sports Edition Hints, Answers for Dec. 16 #449
    • Insurance moves at Starkweather & Shepley and Amica Mutual
    • APCIA supports DRIVER Act to protect vehicle data ownership and privacy
    • Kizzi Kitchener Reveals Why She Didn’t Kiss Below Deck Med Charter Guest David | Bravo
    Global News HQ
    • Technology & Gadgets
    • Travel & Tourism (Luxury)
    • Health & Wellness (Specialized)
    • Home Improvement & Remodeling
    • Luxury Goods & Services
    • Home
    • Finance & Investment
    • Insurance
    • Legal
    • Real Estate
    • More
      • Cryptocurrency & Blockchain
      • E-commerce & Retail
      • Business & Entrepreneurship
      • Automotive (Car Deals & Maintenance)
    Global News HQ
    Home - Legal - OCR’s “Risk Analysis” Enforcement Initiative Continues Against Another Business Associate
    Legal

    OCR’s “Risk Analysis” Enforcement Initiative Continues Against Another Business Associate

    Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp VKontakte Email
    OCR’s “Risk Analysis” Enforcement Initiative Continues Against Another Business Associate
    Share
    Facebook Twitter LinkedIn Pinterest Email


    On August 18, 2025, the Department of Health and Human Services’ Office for Civil Rights (OCR) announced a settlement with BST & Co. CPAs, LLP (BST). The announcement continues OCR’s escalating enforcement of the HIPAA Security Rule, particularly around ransomware and risk analysis inadequacies.

    For the OCR, this is the agency’s 15th ransomware enforcement action and 10th enforcement action in OCR’s Risk Analysis Initiative. For BST, the settlement means the payment of a Resolution Amount of $175,000 and a two-year Corrective Action Plan.

    What Happened?

    The underlying facts outlined in the settlement are all too familiar. BST discovered a ransomware attack in December 2019 triggered by a phishing email. The business associate reported the attack to OCR in February 2020. The attack affected client PHI pertaining to 170,000 individuals.

    BST is a New York–based accounting and business advisory firm that provides services—including tax preparation and forensic accounting—to covered entities. One of BST’s HIPAA covered healthcare provider clients provided BST with financial data that included protected health information (PHI).

    The administrative services BST provided using that PHI caused BST to be a business associate under HIPAA. As a business associate, BST was directly subject to the HIPAA Security Rule—and certain provisions of the Privacy and Breach Notification Rules.

    Business Associates: When thinking about HIPAA, it’s common to focus on healthcare providers. The reality is, however, that for each healthcare provider there are many business associates supporting that provider’s business and, in doing so, processing PHI. These businesses include accounting firms, medical billing firms, transcription services, law firms, practice management consultants, cloud storage providers, and the list goes on.

    OCR’s Risk Analysis Enforcement Initiative

    “A HIPAA risk analysis is essential for identifying where ePHI is stored and what security measures are needed to protect it,” said OCR Director Paula M. Stannard. “Completing an accurate and thorough risk analysis that informs a risk management plan is a foundational step to mitigate or prevent cyberattacks and breaches.”

    Upon investigation, OCR determined that BST had failed to perform an accurate and thorough risk analysis under the HIPAA Security Rule (45 C.F.R. § 164.308(a)(1)(ii)(A)). That lapse, according to OCR, left BST ill-prepared to identify or mitigate vulnerabilities—something OCR has emphasized repeatedly in similar enforcement actions.

    Terms of the Settlement

    To resolve the investigation, BST entered into a resolution agreement with OCR that included:

    • Payment of $175,000.
    • A Corrective Action Plan (CAP), monitored by OCR for two years, which requires BST to:
      1. Conduct a comprehensive risk analysis.
      2. Develop and implement a risk management plan addressing the vulnerabilities identified.
      3. Draft, maintain, and periodically revise written policies and procedures to comply with HIPAA Privacy and Security Rules.
      4. Enhance its HIPAA/security training and deliver annual training to all relevant workforce members.

    What This Means for Business Associates

    This enforcement action is another reminder that business associates are bound by nearly all the same obligations as covered entities when it comes to protecting ePHI.

    Today, data breaches are a near certainty for most organizations. The question is whether an organization is prepared to weather the incident and be strongly positioned to defend an enforcement action by federal or state agencies. In the case of a HIPAA business associate, that means the OCR and its focus on performing a risk analysis. To that end, while not an exhaustive list, business associates should be:

    • Conducting an accurate and thorough risk analysis to assess risks to the confidentiality, integrity, and availability of ePHI.
    • Implementing corresponding risk management plans to mitigate identified risks.
    • Maintain and regularly update written policies and procedures that align with HIPAA Privacy, Security, and, when applicable, Breach Notification Rules.
    • Provide security awareness training tailored to their workforce.
    • If a breach occurs, especially affecting unsecured PHI, promptly notify the covered entity (within 60 days), and supply all necessary details for breach notifications

    HIPAA isn’t just about covered entities—it’s a shared responsibility.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp Email
    Previous ArticleHis Sushi Burger Got 50 Million Views — And Launched a Business | Entrepreneur
    Next Article Trump’s Tariffs Imperil US Black Hair Businesses

    Related Posts

    First-Year Law School Enrollees Increase 13% Since 2023| Law.com

    December 16, 2025

    Structuring Equity Incentives and Profits Interests

    December 16, 2025

    Huge Bonuses And Lindsey Halligan Humiliation – See Also – Above the Law

    December 16, 2025

    ‘You Can See the Concern?’: DC Circuit Hears Argument Over Trump’s Bid to End Most Federal Workers’ Bargaining Rights| Law.com

    December 16, 2025
    Leave A Reply Cancel Reply

    ads
    Don't Miss
    Finance & Investment
    2 Mins Read

    High Yield, High Cost: The Real Returns Of ECC And SLR Investment (NYSE:ECC)

    This article was written byFollowArbitrage Trader, aka Denislav Iliev has been day trading for 15+…

    Client Challenge

    December 16, 2025

    MetaMask adds Bitcoin support after teasing it 10 months ago

    December 16, 2025

    Morning meetings show managers are here to help, not hinder

    December 16, 2025
    Top
    Finance & Investment
    2 Mins Read

    High Yield, High Cost: The Real Returns Of ECC And SLR Investment (NYSE:ECC)

    This article was written byFollowArbitrage Trader, aka Denislav Iliev has been day trading for 15+…

    Client Challenge

    December 16, 2025

    MetaMask adds Bitcoin support after teasing it 10 months ago

    December 16, 2025
    Our Picks
    Finance & Investment
    2 Mins Read

    High Yield, High Cost: The Real Returns Of ECC And SLR Investment (NYSE:ECC)

    This article was written byFollowArbitrage Trader, aka Denislav Iliev has been day trading for 15+…

    Finance & Investment
    1 Min Read

    Client Challenge

    Client Challenge JavaScript is disabled in your browser. Please enable JavaScript to proceed. A required…

    Pages
    • About Us
    • Contact Us
    • Disclaimer
    • Homepage
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube TikTok
    • Home
    © 2025 Global News HQ .

    Type above and press Enter to search. Press Esc to cancel.

    Go to mobile version