An Update on HIPAA Enforcement
While the number of resolution agreements is slightly trending downward, the fines are skyrocketing.
As we reported in June of 2017, the U.S. Department of Health and Human Services (HHS) was on a record pace for the number of enforcement actions it had taken against Covered Entities and Business Associates for violations of the HIPAA Security Rules.
In 2016, it entered into 13 Resolution Agreements, and within the first five months of 2017, they had already brought nine enforcement actions. It appears that any hopes for less enforcement of regulations with a new administration are not panning out.
There has been a slight decline in the number of enforcements taken by the Office for Civil Rights (OCR) since May of 2017. In fact, since that time, there have been a total of 10 additional actions taken.
However, the amount of fines and the average fine per action being levied by OCR has increased dramatically.
Fill out the form below to read more.

Recent Articles View All Thought Leadership
By: Nathan Smith, CPA, Senior Manager at Blue & Co. “You can’t have it both ways” is a sentence many CPAs may have expressed to their clients at one time […]
By Cory Schunemann, Tax Manager at Blue & Co. Tax-exempt organizations frequently grapple with how to report fundraising events on Form 990. The form requires them to separate event proceeds […]
On April 11, 2025, the Centers for Medicare & Medicaid Services (CMS) issued a proposed rule for updates to Medicare payment policies and rates for skilled nursing facilities under the […]