There are few things worse for a health care organization than a breach of PHI. One of them is being fined and/or monitored by HHS OCR after being breached. There are 5 categories of cases that OCR closes.

OCR may decide not to investigate a case further if:
A. It is referred to the Department of Justice for prosecution.
B. It involved a natural disaster.
C. It was pursued, prosecuted, and resolved by state authorities.
D. The covered entity or business associate has taken steps to comply with the HIPAA Rules and OCR determines enforcement resources are better/more effectively deployed in other cases.

Our team is knowledgeable, experienced and fast. We have helped organizations respond to a wide range of breaches and stand up full HIPAA security and privacy programs in a matter of months. Our experts also work with clients (from board level to technical and operations staff) to provide real breach response preparedness and resilience – not just "check-the-box" tabletop breach response exercises.