Risk Analysis Failure Results in Financial Penalty for Comprehensive Neurology

The HHS’ Office for Civil Rights (OCR) has announced another settlement with a HIPAA-regulated entity under its risk analysis enforcement initiative. The $25,000 settlement with the New York healthcare provider, Comprehensive Neurology, is the 8th enforcement action under this initiative to result in a financial penalty, and OCR’s 12th ransomware-related enforcement action.

Comprehensive Neurology experienced a ransomware attack on December 14, 2020, and promptly reported it to OCR. OCR received the notification on December 17, 2020, about a data breach involving the electronic protected health information of 6,800 individuals. The ransomware attack prevented access to patients’ medical records, and information exposed or stolen in the attack included patient names, clinical information, health insurance information, demographic information, Social Security numbers, driver’s license numbers, and state identification numbers.

OCR’s risk analysis enforcement initiative was launched to address the most common HIPAA Security Rule violation. A risk analysis must be conducted to identify risks and vulnerabilities to the confidentiality, integrity, security, and availability of electronic PHI. OCR frequently found that a risk analysis had not been conducted or was not comprehensive and accurate, allowing risks to remain undetected and unresolved. The aim of this enforcement initiative is to highlight the importance of compliance with this HIPAA Security Rule provision and make it clear that risk analysis failures will likely result in financial penalties. Further, by focusing investigations on this implementation specification, OCR can close more investigations and reduce the backlog of data breach cases.

Comprehensive Neurology was found to have failed to conduct a HIPAA-compliant risk analysis and chose to settle the alleged violation. Under the terms of the settlement, a financial penalty of $25,000 will be paid, and a corrective action plan will be implemented with 2 years of monitoring by OCR. The corrective action plan requires a risk analysis to be conducted, risks to be managed and reduced to a low and acceptable level, and policies and procedures developed to ensure HIPAA compliance. Staff members must also receive HIPAA training on those policies and procedures.

“Effective cybersecurity requires proactively implementing the HIPAA Security Rule requirements before a breach or cybersecurity incident occurs,” said OCR Acting Director Anthony Archeval, announcing the settlement. “OCR urges health care entities to prioritize compliance with the HIPAA Security Rule risk analysis requirement.”

OCR Fines and Settlements in 2025

HIPAA-Regulated Entity Penalty Type Amount Reason
Comprehensive Neurology Settlement $25,000 Risk analysis failure
PIH Health, Inc Settlement $600,000 Impermissible disclosure of PHI, risk analysis, HHS notification, individual notifications & media notice
Guam Memorial Hospital Authority Settlement $25,000 Risk analysis failure
Northeast Radiology, P.C. Settlement $350,000 Risk analysis failure
Health Fitness Corporation Settlement $227,816 Risk analysis failure
Oregon Health & Science University Civil Monetary Penalty $200,000 HIPAA Right of Access
Warby Parker, Inc. Civil Monetary Penalty $1,500,000 Risk analysis, risk management, and monitoring activity in information systems containing ePHI
Northeast Surgical Group Settlement $10,000 Risk analysis failure
South Broward Hospital District (Memorial Health System) Settlement $60,000 Right of Access failure
Solara Medical Supplies Settlement $3,000,000 Risk analysis failure, risk management failure, Breach notification failure, impermissible disclosure of the PHI of 114,007 and 1,531 individuals
USR Holdings Settlement $337,750 Risk analysis failure, recording activity in information systems, procedures to create and maintain retrievable exact copies of ePHI, and an impermissible disclosure of the PHI of 2,903 individuals
Virtual Private Network Solutions Settlement $90,000 Risk analysis failure
Elgon Information Systems Settlement $80,000 Risk analysis failure

About Liam Johnson

Liam Johnson has produced articles about HIPAA for several years. He has extensive experience in healthcare privacy and security. With a deep understanding of the complex legal and regulatory landscape surrounding patient data protection, Liam has dedicated his career to helping organizations navigate the intricacies of HIPAA compliance. Liam focusses on the challenges faced by healthcare providers, insurance companies, and business associates in complying with HIPAA regulations. Liam has been published in leading healthcare publications, including The HIPAA Journal. Liam was appointed Editor-in-Chief of The HIPAA Guide in 2023. Contact Liam via LinkedIn: https://www.linkedin.com/in/liamhipaa/