HealthIT Answers June 20, 2025
The risk to privacy and security of healthcare information, despite all of the headlines, does not only come from outside attackers. Inside threats are real and can go undetected for potentially longer periods of time. It has been a bit of time, but the Office for Civil Rights has turned its attention to an insider breach with its most recent settlement of alleged non-compliance with HIPAA.
The Factual Background
So what happened that caught OCR’s attention? It began with a complaint received by OCR on October 23, 2018. The complaint alleged that on October 8, 2018 an unknown individual accessed the complainant’s medical record at St. Joseph’s Hospital, which is operated by BayCare Health System (BayCare). The complainant learned about...







