Oct 5, 2026

News

A $700,000 Phishing Settlement and OCR's Favorite Question: Do You Have a Current Risk Analysis?

One phishing email, sent in January 2020, just cost a healthcare company $700,000 — and the HIPAA violation that sealed it wasn't the phishing email itself. It was something OCR investigators ask about in nearly every case they open: do you have a current, accurate risk analysis on file?

What actually happened

On September 17, 2026, the HHS Office for Civil Rights announced a $700,000 settlement with Ambry Genetics, a California-based genetic testing lab, after a phishing attack compromised an employee's email account and exposed protected health information for 225,370 people — names, Social Security numbers, driver's license numbers, diagnoses, lab results, and treatment information among it. Ambry also separately settled a related class-action lawsuit for $12.25 million.

The phishing email is what got attackers in. But when OCR investigated, it didn't center its findings on the email. It cited three specific failures: no accurate, thorough risk analysis of threats to electronic patient data; no process for cutting off a former employee's system access; and no unique login credentials to track who touched what inside systems holding patient records. OCR Director Paula M. Stannard tied the settlement back to a theme her office has repeated in nearly every recent action: risk analysis, risk management, and full implementation of the HIPAA Security Rule remain the foundation every covered entity is expected to have in place before an attack, not after one.

Ambry isn't an outlier case — it's one entry in a pattern. OCR has now pursued more than a dozen settlements tied specifically to missing or outdated risk analyses, and roughly twenty tied to ransomware incidents, under an enforcement effort it's been running since October 2024. The organizations range from large health systems down to a software vendor serving dental offices and a behavioral health clinic with 14,000 affected patients. Size hasn't been a shield in any of them.

Why it matters

Here's the part that should change how you think about compliance: OCR doesn't need you to have caused a breach through negligence to find you liable. It needs you to be unable to produce a document. Every one of these settlements started with an incident — a phishing email, a stolen laptop, a vendor's ransomware attack — and then investigators asked the same first question: show us your current risk analysis. When practices can't produce one that's accurate, dated, and specific to their own systems, that absence becomes the violation that drives the settlement, regardless of how the breach itself happened.

That also means a risk analysis isn't a one-time project you can point to from three years ago. OCR has specifically flagged "current" and "accurate" analyses — one that reflects the EHR you're on today, the cloud tools your staff actually uses, and the vendors with access to your systems right now, not the ones you had when you last hired a consultant to check a box.

What this means if you're a South Florida practice

None of the organizations in these settlements are hospital systems with dedicated security teams. A dental software vendor and a behavioral health clinic serving a few thousand patients were both targets of the same enforcement initiative as multi-state health networks. If your practice is a two-to-ten-provider operation in Palm Beach, Broward, or Miami-Dade — or one of the practices we're increasingly supporting as we extend our HIPAA-focused IT services up into Martin and St. Lucie counties — "we're too small for OCR to notice" isn't a defense anyone has successfully used in these cases. The breach itself is frequently caused by something ordinary: one employee clicking one bad link. What decides whether that becomes a six-figure settlement is the paperwork you can or can't produce afterward.

The good news is that a risk analysis is one of the more straightforward things to get right, compared to, say, redesigning your entire network. It doesn't require predicting every possible attack. It requires an honest, documented inventory of where patient data lives, who can access it, and what happens if each access point is compromised — updated at least annually or whenever something material changes (new EHR, new vendor, new remote work policy).

Practical takeaways

  • Find your most recent documented risk analysis. If you can't locate one, or it predates your current EHR or major vendors, that's your most urgent compliance gap today.

  • Confirm it covers every system that touches patient data, not just your EHR — scheduling software, patient portals, fax/email, and any AI tools staff may be using.

  • Check your offboarding process: when someone leaves, is their system access actually revoked, and is that documented?

  • Verify every account accessing patient records uses a unique login — shared logins are a specific, named failure in multiple recent OCR settlements.

  • Ask your IT provider or practice manager when your last risk analysis was dated, and put a recurring reminder on the calendar to redo it at least yearly.

A risk analysis won't stop every phishing email. But it's the one document that, time and again, has decided whether a bad click costs a practice a corrective action plan or a six-figure check.

Get expert clarity

Frequently asked questions

Can my staff use the free version of ChatGPT or Claude at work?

Yes, for tasks with no patient information at all, like drafting a generic handout or a job posting. Never for anything touching a patient’s chart or PHI, per both companies’ own consumer terms.

What is a BAA and why does it matter for AI tools?

A Business Associate Agreement is a signed contract required under HIPAA before any vendor can touch PHI on your behalf. Anthropic and OpenAI only offer BAAs on business-tier or API plans, and it must be separately executed, not assumed from a paid subscription.

Does paying for ChatGPT Plus or Claude Pro make it HIPAA-compliant?

No. Both companies state that even paid individual consumer accounts (Plus, Pro, Max) are not covered by a BAA and PHI should not be entered into them.

What should our practice do before letting staff use AI with patient information?

Confirm a business-tier account is provisioned with an executed BAA, set a written policy distinguishing PHI from non-PHI use cases, and fold AI access into your existing audit-logging and access-review process.

How does UpsiteGroup help with this?

We confirm which AI tools your staff can access, verify a BAA is actually on file (not just technically available), and manage AI access controls alongside your EHR’s existing security configuration.

Faded abstract map pattern behind the closing call to action

Build smarter systems and grow with confidence

Faded abstract map pattern behind the closing call to action

Build smarter systems and grow with confidence