Missing Risk Analysis Cost NY CPA Firm $175KβBut Not the Big Group Whose Data Was Breached in 2019
9 October 2025 at 09:41
Theresa Defino reports: Covered entities (CEs) and business associates (BAs) might be forgiven if the most recent HHS Office for Civil Rights (OCR) HIPAA enforcement action evoked little more than a yawn. Yes, the $175,000 payment isnβt a particularly large amount, and the sole alleged violation is a retread. Actually, itβs the 10th in OCRβs...

