Azul HIPAA settlement

HIPAA has always been about patients’ rights. Over its 30-year history, HIPAA has put patients at the center by protecting patient privacy and giving patients access to their medical records

Today, patient rights remain central to HIPAA enforcement.

On August 27, 2026, the Office for Civil Rights (OCR) announced its 55th enforcement action under the HIPAA Right of Access Initiative. OCR’s target was Azul Vision, Inc. an ophthalmology service provider operating across Southern California.

The settlement, which includes a $50,000 monetary penalty and a two-year Corrective Action Plan (CAP), reminds healthcare providers to pay attention to patients’ requests. Timely access to protected health information (PHI) is not optional. It is a strict legal mandate, aggressively enforced, regardless of an organization’s structure, location, or size.

An Azul Patient Waited for Months

OCR investigated after an Azul patient complained in April, 2023. She had first requested access 30 days earlier, in January. She made multiple requests, and yet Azul didn’t comply.

OCR’s investigation confirmed that Azul Vision failed to provide the patient with her records within the timeframe required by HIPAA.

The HIPAA Privacy Rule requires covered entities to act on an individual’s request no later than 30 calendar days after receipt. Although a single 30-day extension is permitted in limited circumstances, the covered entity must provide a written explanation for the delay and a definitive completion date before the initial 30 days expire.

In addition to paying the $50,000 resolution amount, Azul Vision entered into a two-year Corrective Action Plan (CAP) under OCR’s oversight. Azul Vision must do the following:

  1. Revise Policies and Procedures: Develop and implement updated written policies governing individual access to PHI.
  2. Standardize Staff Training: Distribute updated access policies to all workforce members and conduct mandatory training programs within 60 days.
  3. Institute Internal Tracking: Implement tracking mechanisms to record the receipt, processing, and completion of all record requests.
  4. Submit Compliance Reports: Provide annual compliance reports and document any failures to fulfill access requests within the required timeframe directly to OCR for two full years.

A Universal Mandate: Covered Entities of All Types and Sizes Are Targeted

A common misconception among smaller clinics, specialized medical groups, and business associates is that OCR enforcement targets only large health systems or bigger corporate data breaches. The Right of Access Initiative proves otherwise.

Since OCR launched the initiative in 2019, the agency has brought 55 enforcement actions spanning the entire healthcare ecosystem:

  • Solo and Small Group Practices: Podiatry practices, dental clinics, solo primary care doctors, and small psychiatric groups have paid fines ranging from $3,500 to $100,000.
  • Specialty Management Groups: Entities like Azul Vision, which manages multiple eye care clinics and surgical centers, show that management organizations share full liability.
  • Large Academic Medical Centers: Major hospital systems have faced six-figure penalties for delayed record access due to internal administrative bottlenecks or improper fee calculations.
  • Behavioral Health Providers: Mental health facilities have faced sanctions for improperly withholding records because they misinterpret safety exceptions or psychotherapy note definitions.

The HIPAA Privacy Rule is clear: OCR evaluates right-of-access violations based on their impact on the patient, not the covered entity’s size or financial resources. Whether a provider handles 10 requests a month or 10,000, failing to deliver records within 30 days exposes the entity to direct monetary penalties.

The Risk Analysis Initiative

While the Right of Access Initiative highlights patient privacy rights, OCR also focuses on failed safeguards under the HIPAA Security Rule.

Six OCR enforcement actions announced in 2026 focus on Risk Analysis failures under the Security Rule. OCR noted a failed Risk Analysis in all of the following:

  1. OSF Healthcare ($552,250): A ransomware attack affected 53,907 individuals; OSF failed to provide timely breach notification in addition to the failed risk analysis.
  2. Assured Imaging ($375,000): Mobile mammography and imaging provider (244,813 individuals affected) experienced a ransomware attack.
  3. RWHG / Renaissance Women’s Health Group ($320,000): Specialty women’s healthcare provider: a ransomware incident exposed the data of 37,989 individuals.
  4. Star Group Health Plan ($245,000): Self-funded employee benefit health plan experienced a ransomware attack affecting 9,316 plan members.
  5. Consociate Health ($225,000): Third-Party Administrator (TPA) and Business Associate; the breach affected 136,539 individuals.
  6. Top of the World Ranch Treatment Center ($103,000 Settlement): A phishing attack exposed PHI through an employee email account at this substance use treatment provider.

In every major Security Rule investigation, OCR penalizes covered entities and business associates not simply because they were victims of a cyberattack, but because they failed to conduct a complete enterprise-wide Risk Analysis.

Common compliance gaps include:

  • Incomplete Asset Inventories: Failing to include all databases, legacy servers, laptops, mobile devices, and cloud storage that hosts PHI in the risk assessment.
  • Stale or One-Time Risk Assessments: Treating Risk Analysis as a static checklist item rather than an ongoing evaluation.
  • Failure to Mitigate Known Vulnerabilities: Identifying technical security gaps during a review but failing to implement timely risk management plans to remediate them.

OCR continues to emphasize that a thorough, documented Risk Analysis is the cornerstone of HIPAA compliance. Without it, entities face severe financial penalties in the event of a ransomware attack.

Looking to the Future: The Evolving Privacy Rule and Right of Access

The strategic emphasis on patient access and modern health data sharing is built to last. In a recent video address marking HIPAA’s 30th anniversary, OCR Director Paula Stannard reflected on the evolving legal landscape for health information privacy and security.

Director Stannard highlighted ongoing federal efforts to update and finalize proposed modifications to the HIPAA Privacy Rule. These upcoming regulatory changes aim to:

  • Strengthen Individual Access Rights: Streamline how patients access, obtain, and direct electronic copies of their health records to personal health apps.
  • Enhance Care Coordination: Reduce administrative hurdles so healthcare providers can seamlessly share essential patient information to deliver care.
  • Promote Interoperability: Align HIPAA standards with broader federal health IT mandates to enable secure data exchange across healthcare platforms.

As Director Stannard noted, HIPAA was designed to be flexible enough to accommodate emerging technologies while maintaining privacy protections. The upcoming Privacy Rule revisions will reinforce patient empowerment and require covered entities to modernize their workflow systems to enable rapid access.

Prevent an Investigation and Penalties

To avoid becoming the next OCR target or facing penalties following a security incident, organizations should audit their policies and procedures:

  1. Review Records Access Policies: Ensure that written policies mandate a 30-day response window and specify the narrow criteria for an extension.
  2. Eliminate Unlawful Barriers: Remove unapproved request forms, mandatory notarization requirements, or excessive fee schedules.
  3. Conduct an Enterprise-Wide Risk Analysis: Inventory all locations of PHI (both electronic and non-electronic) across your organization, and conduct business associate due diligence.
  4. Train Staff: Educate front-office staff and medical records personnel on proper intake and escalation procedures.

Stay Compliant with The HIPAA E-Tool®

Managing evolving regulatory mandates, Right of Access protocols, and Security Rule compliance requires robust, operational software. The HIPAA E-Tool® provides covered entities and business associates with policies, a step-by-step risk analysis module, staff training, and supportive forms and templates to keep organizations fully compliant.

Visit The HIPAA E-Tool® today to schedule a demo and protect your organization from enforcement penalties.

Free HIPAA Checklist
What best describes you?