Northeast Radiology Pays $350,000 Penalty for Alleged Risk Analysis Failure

Northeast Radiology, P.C., has agreed to settle an alleged violation of the risk analysis implementation specification of the HIPAA Security Rule with the Department of Health and Human Services’ Office for Civil Rights (OCR). The settlement agreement includes a $350,000 financial penalty, a corrective action plan, and monitoring of compliance by OCR for 2 years.

OCR launched an investigation after receiving a breach report in March 2020 from Northeast Radiology about a hacking incident involving the protected health information of up to 298,532 individuals. Northeast Radiology and its vendor Alliance HealthCare Services were notified about vulnerabilities in their Picture Archiving and Communication System (PACS) by security researchers in December 2019, and after investigating, determined that hackers had accessed the PACS between April 2019 and January 2020 and stolen sensitive data. The types of data stolen in the incident included medical images such as X-rays, CT scans, and MRIs, and protected health information such as names, test results, medical record numbers, dates of service, and Social Security numbers.

OCR has launched a HIPAA enforcement initiative specifically looking at compliance with 45 C.F.R. § 164.308(a)(1)(ii)(A) of the HIPAA Security Rule – the risk analysis. The risk analysis is fundamental to the cybersecurity of an organization, as it ensures that all potential risks and vulnerabilities are identified and can then be subjected to a risk management process and reduced to a low and acceptable level.  If a risk analysis is not conducted, or if it is not comprehensive and accurate, risks are likely to remain unresolved and could be exploited by malicious actors.

OCR’s investigation of the Northeast Radiology data breach confirmed that a HIPAA-compliant risk analysis had not been conducted, and the compliance failure warranted a financial penalty. Northeast Radiology was given an opportunity to settle the matter informally and accepted, resulting in a reduced penalty. The corrective action plan includes the requirement to conduct a comprehensive and accurate risk analysis, develop a risk management process to address any identified risks, develop policies and procedures to ensure HIPAA compliance, provide HIPAA training to the workforce on those policies, and enhance its security training program. Northeast Radiology must also develop and implement a process to regularly review records of activity in information systems containing ePHI.

This is the sixth OCR enforcement action under its risk analysis enforcement initiative and the fourth financial penalty to be imposed by OCR under the Trump administration to resolve alleged HIPAA violations. So far in 2025, 10 enforcement actions have been announced by OCR, with $5,627,750 paid in settlements and civil monetary penalties. “A HIPAA risk analysis is essential to identifying where electronic protected health information is stored, and the security measures in place to protect it,” said OCR Acting Director Anthony Archeval, announcing the settlement. “A failure to conduct a risk analysis often foreshadows a future HIPAA breach.”

About Liam Johnson

Liam Johnson has produced articles about HIPAA for several years. He has extensive experience in healthcare privacy and security. With a deep understanding of the complex legal and regulatory landscape surrounding patient data protection, Liam has dedicated his career to helping organizations navigate the intricacies of HIPAA compliance. Liam focusses on the challenges faced by healthcare providers, insurance companies, and business associates in complying with HIPAA regulations. Liam has been published in leading healthcare publications, including The HIPAA Journal. Liam was appointed Editor-in-Chief of The HIPAA Guide in 2023. Contact Liam via LinkedIn: https://www.linkedin.com/in/liamhipaa/