Vision Upright MRI Settles Alleged HIPAA Violations for $5,000

A small Californian medical imaging service provider has been discovered to be in violation of the HIPAA Rules and has been fined $5,000 for the compliance failures. Vision Upright MRI conducts magnetic resonance imaging (MRI) scans and provides related services at a single facility in San Jose, California.

OCR launched an investigation of the practice in early December 2020 to assess compliance with the HIPAA Rules. The investigation revealed Vision Upright MRI had experienced a breach of the electronic protected health information (ePHI) of 21,778 individuals, yet the data breach was not disclosed to OCR, notifications had not been sent to the affected individuals, and a media notice had not been issued. The ePHI was stored on a server housing its Picture Archiving and Communication System (PACS), which is used for storing, retrieving, managing, and accessing radiology images. The server had not been secured, and ePHI could be, and was, accessed by unauthorized individuals.

OCR also determined that Vision Upright MRI had never conducted a comprehensive and accurate risk analysis to identify all risks and vulnerabilities to ePHI. A consequence of that failure is that risks and vulnerabilities likely remain unaddressed, as was the case here, as ePHI had been left unsecured on a server that could be accessed over the Internet.

When OCR identifies HIPAA violations, technical assistance is often provided to help the regulated entity comply with the HIPAA Rules; however, if the violations are severe enough to warrant a financial penalty, OCR usually gives the affected entity an opportunity to settle the alleged violations informally. A settlement agreement will include a financial penalty and a corrective action plan to address the identified compliance failures. Financial penalties are significantly reduced if the entity opts to settle.

Vision Upright MRI opted to settle the case and agreed to pay a $5,000 penalty and adopt a corrective action plan. Vision Upright MRI will be monitored by OCR for two years to ensure compliance with the corrective action plan. Vision Upright MRI must issue notification letters to OCR, the affected individuals, and must issue a media notice about the data breach. A risk analysis must be conducted to identify risks and vulnerabilities to ePHI, and a risk management plan must be developed and implemented to reduce risks to an acceptable level. OCR must be provided with evidence that the risk analysis has been completed and a copy of the risk management plan.

Vision Upright MRI must develop, implement, and maintain policies and procedures to ensure compliance with the HIPAA Privacy Rule, Security Rule, and Breach Notification Rule, and distribute those policies to the workforce. The workforce must receive HIPAA training on those policies and procedures.

HIPAA
Compliance
Checklist

Simple Guidelines
Immediate PDF Download

Immediate Access

Privacy Policy

Download Free Checklist

“Cybersecurity threats affect large and small covered health care providers,” said OCR Acting Director Anthony Archeval, announcing the settlement agreement. “Small providers also must conduct accurate and thorough risk analyses to identify potential risks and vulnerabilities to protected health information and secure them.”

This is the eighth financial penalty to be imposed by OCR under the Trump administration in 2025, and the 14th HIPAA fine of the year. So far this year, OCR has collected $6,510,566 in HIPAA penalties. Twelve of the 15 penalties announced this year have involved risk analysis failures.

About Liam Johnson

Liam Johnson has produced articles about HIPAA for several years. He has extensive experience in healthcare privacy and security. With a deep understanding of the complex legal and regulatory landscape surrounding patient data protection, Liam has dedicated his career to helping organizations navigate the intricacies of HIPAA compliance. Liam focusses on the challenges faced by healthcare providers, insurance companies, and business associates in complying with HIPAA regulations. Liam has been published in leading healthcare publications, including The HIPAA Journal. Liam was appointed Editor-in-Chief of The HIPAA Guide in 2023. Contact Liam via LinkedIn: https://www.linkedin.com/in/liamhipaa/