Risk Analysis Failure Results in Financial Penalty for Comprehensive Neurology
The HHS’ Office for Civil Rights (OCR) has announced another settlement with a HIPAA-regulated entity under its risk analysis enforcement initiative. The $25,000 settlement with the New York healthcare provider, Comprehensive Neurology, is the 8th enforcement action under this initiative to result in a financial penalty, and OCR’s 12th ransomware-related enforcement action.
Comprehensive Neurology experienced a ransomware attack on December 14, 2020, and promptly reported it to OCR. OCR received the notification on December 17, 2020, about a data breach involving the electronic protected health information of 6,800 individuals. The ransomware attack prevented access to patients’ medical records, and information exposed or stolen in the attack included patient names, clinical information, health insurance information, demographic information, Social Security numbers, driver’s license numbers, and state identification numbers.
OCR’s risk analysis enforcement initiative was launched to address the most common HIPAA Security Rule violation. A risk analysis must be conducted to identify risks and vulnerabilities to the confidentiality, integrity, security, and availability of electronic PHI. OCR frequently found that a risk analysis had not been conducted or was not comprehensive and accurate, allowing risks to remain undetected and unresolved. The aim of this enforcement initiative is to highlight the importance of compliance with this HIPAA Security Rule provision and make it clear that risk analysis failures will likely result in financial penalties. Further, by focusing investigations on this implementation specification, OCR can close more investigations and reduce the backlog of data breach cases.
Comprehensive Neurology was found to have failed to conduct a HIPAA-compliant risk analysis and chose to settle the alleged violation. Under the terms of the settlement, a financial penalty of $25,000 will be paid, and a corrective action plan will be implemented with 2 years of monitoring by OCR. The corrective action plan requires a risk analysis to be conducted, risks to be managed and reduced to a low and acceptable level, and policies and procedures developed to ensure HIPAA compliance. Staff members must also receive HIPAA training on those policies and procedures.
“Effective cybersecurity requires proactively implementing the HIPAA Security Rule requirements before a breach or cybersecurity incident occurs,” said OCR Acting Director Anthony Archeval, announcing the settlement. “OCR urges health care entities to prioritize compliance with the HIPAA Security Rule risk analysis requirement.”
OCR Fines and Settlements in 2025
| HIPAA-Regulated Entity | Penalty Type | Amount | Reason |
| Comprehensive Neurology | Settlement | $25,000 | Risk analysis failure |
| PIH Health, Inc | Settlement | $600,000 | Impermissible disclosure of PHI, risk analysis, HHS notification, individual notifications & media notice |
| Guam Memorial Hospital Authority | Settlement | $25,000 | Risk analysis failure |
| Northeast Radiology, P.C. | Settlement | $350,000 | Risk analysis failure |
| Health Fitness Corporation | Settlement | $227,816 | Risk analysis failure |
| Oregon Health & Science University | Civil Monetary Penalty | $200,000 | HIPAA Right of Access |
| Warby Parker, Inc. | Civil Monetary Penalty | $1,500,000 | Risk analysis, risk management, and monitoring activity in information systems containing ePHI |
| Northeast Surgical Group | Settlement | $10,000 | Risk analysis failure |
| South Broward Hospital District (Memorial Health System) | Settlement | $60,000 | Right of Access failure |
| Solara Medical Supplies | Settlement | $3,000,000 | Risk analysis failure, risk management failure, Breach notification failure, impermissible disclosure of the PHI of 114,007 and 1,531 individuals |
| USR Holdings | Settlement | $337,750 | Risk analysis failure, recording activity in information systems, procedures to create and maintain retrievable exact copies of ePHI, and an impermissible disclosure of the PHI of 2,903 individuals |
| Virtual Private Network Solutions | Settlement | $90,000 | Risk analysis failure |
| Elgon Information Systems | Settlement | $80,000 | Risk analysis failure |