logo

HHS Office for Civil Rights Settles HIPAA Cybersecurity Investigation with Vision Upright MRI

ID: d4bfb0d5-9622-52af-b2de-bfa016a558e1

STIX ID: report--d4bfb0d5-9622-52af-b2de-bfa016a558e1

Feed Name: DataBreaches.Net

Threat Score
56/100

Date Published: 2025-05-16

Date Updated: 2026-04-19

Author: Dissent

...
...

HHS/OCR announced an enforcement action against Vision Upright MRI after an unauthorized third party accessed ePHI on the provider’s PACS server, exposing medical images of 21,778 patients (23,031 reported to HHS). OCR found the provider failed to perform a HIPAA risk analysis and did not notify affected individuals within 60 days; the organization agreed to a two-year corrective action plan and a $5,000 payment, with required measures including breach notifications, risk analysis, risk management, updated policies, and workforce training (timeline of discovery not specified).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.