Breach of Unsecured Server Results in Monetary Penalty and Corrective Action Plan

6/1/2025
The U.S. Department of Health and Human Services (DHHS) recently entered into a Resolution Agreement with an imaging provider relating to the breach of a picture and archiving communications system (PACS) server containing medical images of its patients. The investigation of the provider was initiated by the DHHS Office for Civil Rights (OCR) after OCR obtained information alleging that protected health information maintained or stored by the provider was accessible via the internet and disclosed as the result of an unsecure PACS server. Per the Resolution Agreement, the investigation revealed that the provider “never conducted an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of the electronic protected health information that it holds,” as required by the HIPAA Security Rule, and the provider “failed to notify affected individuals of a breach within 60 days of discovery of the breach,” as required by the HIPAA Breach Notification Rule.