HHS Settles Phishing Attack Investigation for $600,000

The HHS’ Office for Civil Rights (OCR) has settled an investigation of a phishing attack that saw 35 accounts compromised. PIH Health must pay a $600,000 financial penalty to resolve multiple alleged violations of the HIPAA Rules.

On January 10, 2020, the California healthcare network PIH Health notified OCR about a phishing incident that occurred between June 11 and June 19, 2019. Many phishing attacks on healthcare organizations result in a single email account compromise, or a few employees are tricked by phishing emails, although in the case of PIH Health, 45 email accounts were compromised and accessed following employee responses to phishing emails. The accounts contained the electronic protected health information (ePHI) of 189,763 individuals.

OCR launched an investigation on April 29, 2020, into the data breach to determine if PIH Health was compliant with the HIPAA Rules. The investigation uncovered multiple areas of noncompliance, including the failure to conduct a thorough and accurate risk analysis to identify risks and vulnerabilities to ePHI, and the impermissible disclosure of the ePHI of 189,763 individuals, with the former violating the HIPAA Security Rule and the latter violating the HIPAA Privacy Rule.

OCR also identified three HIPAA Breach Notification Rule Failures. PIH Health did not notify the Secretary of the HHS about the data breach, issue individual notification letters, or issue a media notice about the data breach in a timely manner. HIPAA-covered entities must issue notifications without undue delay and no later than 60 days from the date of discovery of a data breach.

Usually, when OCR identifies serious HIPAA violations that warrant a financial penalty, the regulated entity is provided with an opportunity to settle the alleged violations informally, as was the case with PIH Health. The agreed settlement includes a $600,000 financial penalty, a corrective action plan (CAP), and two years of monitoring by OCR.

The CAP requires PIH Health to conduct a comprehensive and accurate risk analysis; develop and implement a risk management plan to reduce identified risks and vulnerabilities; and develop, implement, and maintain policies and procedures to ensure HIPAA compliance. Those policies must be distributed to all members of the workforce who have access to ePHI, and HIPAA training must be provided.

HIPAA
Compliance
Checklist

Simple Guidelines
Immediate PDF Download

Immediate Access

Privacy Policy

Download Free Checklist

This was the sixth financial penalty to be imposed by OCR this year under the Trump administration and the second-largest penalty of the year behind the $1.5 million civil monetary penalty imposed on Warby Parker. So far in 2025, OCR has announced 12 financial penalties to resolve HIPAA violations.

OCR Fines and Settlements in 2025

HIPAA-Regulated Entity Penalty Type Amount Reason
PIH Health, Inc Settlement $600,000 Impermissible disclosure of PHI, risk analysis, HHS notification, individual notifications & media notice
Guam Memorial Hospital Authority Settlement $25,000 Risk analysis
Northeast Radiology, P.C. Settlement $350,000 Risk analysis
Health Fitness Corporation Settlement $227,816 Risk analysis
Oregon Health & Science University Civil Monetary Penalty $200,000 HIPAA Right of Access
Warby Parker, Inc. Civil Monetary Penalty $1,500,000 Risk analysis, risk management, and monitoring activity in information systems containing ePHI
Northeast Surgical Group Settlement $10,000 Risk analysis failure
South Broward Hospital District (Memorial Health System) Settlement $60,000 Right of Access failure
Solara Medical Supplies Settlement $3,000,000 Risk analysis failure, risk management failure, Breach notification failure, impermissible disclosure of the PHI of 114,007 and 1,531 individuals
USR Holdings Settlement $337,750 Risk analysis failure, recording activity in information systems, procedures to create and maintain retrievable exact copies of ePHI, and an impermissible disclosure of the PHI of 2,903 individuals
Virtual Private Network Solutions Settlement $90,000 Risk analysis failure
Elgon Information Systems Settlement $80,000 Risk analysis failure

About Liam Johnson

Liam Johnson has produced articles about HIPAA for several years. He has extensive experience in healthcare privacy and security. With a deep understanding of the complex legal and regulatory landscape surrounding patient data protection, Liam has dedicated his career to helping organizations navigate the intricacies of HIPAA compliance. Liam focusses on the challenges faced by healthcare providers, insurance companies, and business associates in complying with HIPAA regulations. Liam has been published in leading healthcare publications, including The HIPAA Journal. Liam was appointed Editor-in-Chief of The HIPAA Guide in 2023. Contact Liam via LinkedIn: https://www.linkedin.com/in/liamhipaa/