The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has announced a settlement with Vision Upright MRI, a small healthcare provider in California, following serious HIPAA violations involving the exposure of over 21,000 patients’ medical images. The breach stemmed from an unsecured Picture Archiving and Communication System (PACS) server that stored electronic protected health information (ePHI).
OCR launched its investigation after learning of unauthorized access to the server by a third party. During the review, it was revealed that Vision Upright MRI had never conducted a HIPAA risk analysis, a core requirement under the HIPAA Security Rule. The provider also failed to notify the 21,778 affected individuals within the 60-day timeframe mandated by the Breach Notification Rule.
To resolve these violations, Vision Upright MRI agreed to pay $25,000 and adopt a Corrective Action Plan, which includes two years of federal oversight. Key steps required under the plan include:
- Issuing proper breach notifications to individuals, HHS, and the media
- Conducting and submitting a comprehensive risk analysis covering all systems that store or transmit ePHI
- Implementing a risk management plan to address vulnerabilities
- Creating and updating HIPAA-compliant policies and procedures
- Training all staff with access to ePHI
OCR emphasized that cybersecurity is not just a large-provider problem. “Small providers also must conduct accurate and thorough risk analyses,” said OCR Acting Director Anthony Archeval.
This case underscores the need for all HIPAA-covered entities—regardless of size—to take proactive measures to secure patient data. OCR recommends identifying where ePHI resides, encrypting data, enforcing access controls, and providing ongoing HIPAA training.
For organizations handling protected health information, failure to comply with HIPAA can lead not only to fines but also to reputational damage and federal scrutiny. Don’t wait for a breach to act.
Read more about the settlement here:
Vision Upright MRI HIPAA Settlement
image sources
- pexels-tara-winstead-7723513: Photo by Tara Winstead