HHS secures $175,000 HIPAA settlement over phishing ransomware breach

The case underscores HHS’s growing focus on business associates and the Risk Analysis Enforcement Initiative.

The HHS Office for Civil Rights (HHS OCR) announced a settlement with BST & Co CPAs, LLP, a New York-based public accounting, business advisory, and management consulting firm.

The settlement resolves a HIPAA Security Rule violation related to a ransomware incident that affected the electronic personal health information (ePHI) of

Free Trial

Register for free to keep reading.

To continue reading this article and unlock full access to GRIP, register now. You’ll enjoy free access to all content until our subscription service launches in early 2026.

  • Unlimited access to industry insights
  • Stay on top of key rules and regulatory changes with our Rules Navigator
  • Ad-free experience with no distractions
  • Regular podcasts from trusted external experts
  • Fresh compliance and regulatory content every day
Register for free Already a member? Sign in