Exercise Caution in Posting Patient Success Stories
11/1/2025
The U.S. Department of Health & Human Services recently announced the settlement by the Office for Civil Rights (OCR) of allegations of HIPAA violations against Cadia Healthcare Facilities relating to posting a patient’s name, photograph and information about the patient’s conditions, treatment, and recovery in the form of a “success story” on Cadia Healthcare Facilities’ website. OCR concluded the posting was made without obtaining a valid, HIPAA-compliant authorization from the patient and, in addition, that Cadia Healthcare Facilities disclosed the protected health information (PHI) of 150 patients to its websites through its “success story” program without patient authorization. OCR determined that Cadia Healthcare Facilities:
• Impermissibly disclosed PHI,
• Failed to have appropriate administrative, technical and physical safeguards in place to protect the privacy of PHI, and
• Failed to provide breach notification to the affected individuals.
Under the terms of a resolution agreement entered into between Cadia Healthcare Facilities and OCR, the provider agreed to pay a civil penalty of $182,000 and to implement a corrective action plan that will be monitored by the OCR for two years.
