- HIPAA enforcement is costly: To date, the HHS Office for Civil Rights has issued 152 enforcement actions, totalling nearly $145 million in penalties. In 2024 alone, settlements exceeded $9 million across healthcare organizations.
- Data breaches are rising: Healthcare reported 725 large data breaches in 2023, affecting over 133 million records.
- California adds extra layers: CPRA fines can reach $7,500 per violation, with enforcement now led by the California Privacy Protection Agency.
- Patient Access to Health Information
- HIPAA requires records to be provided within 30 days (best practice: 7 days).
- California’s CMIA adds stricter requirements for storage, disposal, and breach response.
- Privacy & Consumer Data (CPRA / CCPA)
- Applies to data outside of HIPAA PHI, including marketing, website visitors, and HR data.
- No more 30-day cure period for violations; fines can be immediate.
- Infection Control & OSHA Requirements
- OSHA’s Bloodborne Pathogens Standard requires written exposure-control plans, annual training, PPE, and vaccination protocols.
- California enforces 16 CCR §1005, mandating written infection-control policies, sterilization logs, and post-exposure procedures.
- Imaging & Radiation Safety
- CBCT and X-ray units must be registered and tracked under a Radiation Protection Program.
- Handheld devices carry special oversight.
- Staff must maintain radiation-safety certification and documented training.
- Vendor & Technology Partnerships
- Business Associate Agreements (BAAs) required for all vendors handling PHI.
- Data Processing Agreements (DPAs) needed for CPRA-covered consumer data.
- Dual compliance burden: HIPAA + CMIA + CPRA all apply.
- Record retention rules: Keep patient records 7 years minimum; for minors, until 1 year after age 18.
- Privacy enforcement: The CPPA (California Privacy Protection Agency) can now independently issue penalties.
- Infection-control enforcement: The Dental Board audits compliance with 16 CCR §1005 as part of site inspections.
- Compliance dashboards track record access times, OSHA training, and audit scores.
- Internal SLAs: e.g., fulfilling patient record requests within 7 days.
- Quarterly audits ensure consistency in infection control and radiation logs.
- Vendor due diligence closes gaps in PHI and consumer-data handling.
| Domain | Key Action | Target |
| Record Access | Fulfill requests ≤7 days | Avoid HIPAA penalties |
| Privacy | Segment PHI vs. non-PHI, apply CPRA | Full dual compliance |
| Infection Control | Quarterly audits + annual training | ≥95% audit score |
| Radiation | QA logs, staff certs, unit registration | 100% compliance |
| Vendor Contracts | BAAs (PHI), DPAs (non-PHI) | Zero vendor gaps |
- HHS OCR Enforcement Highlights
- HIPAA Journal – Violation Fines
- LegalHIE – 2024 HIPAA Enforcement Review
- HIPAA Journal – Data Breach Statistics
- California-CCPA.org – CPRA Fines & Penalties
- California OAG – Privacy Enforcement Actions
- IAPP – CPRA Enforcement Overview
- CADP – About & QA Certification
- NADP – Association Overview