Pulse July 8, 2025
The drumbeat of settlement agreements for alleged HIPAA violations by the Office for Civil Rights is continuing along with the consistent finding that the required risk analysis did not occur. The consistent announcement of settlements offers regular reminders to the healthcare industry that OCR is watching and expecting compliance to improve. The almost always present finding that a risk analysis did not occur is a reminder that this fundamental element of HIPAA Security Rule compliance is occurring too infrequently.
The Newest Settlement
The most recent settlement announcement from OCR came on July 7, 20225, and impacted Deer Oaks – The Behavioral Health Solution (“Deer Oaks”). Deer Oaks is an affiliated covered entity, which means a group of organizations agreed to...







