Back to Enforcement
HIPAA Enforcement · 23 cases · 2017–2025

$92M+ in Fines for
Healthcare Audit Trail Failures

Hackers lived in systems for 17 months undetected. Insiders stole patient data for 6 months before police noticed. The common thread: no functioning audit trail to detect unauthorized access.

Featured Cases

Premera Blue Cross

September 2020

$6.85M

Second-largest HIPAA penalty at the time. Hackers accessed systems and exfiltrated ePHI of 10.4 million individuals. Breach went undetected for approximately nine months. Failed to conduct enterprise-wide risk analysis and implement sufficient audit controls.

Source: HHS OCR

Memorial Healthcare System

February 2017

$5.5M

Login credentials of a former employee were used daily for an entire year to access ePHI of 80,000 patients. Shared login credentials made it impossible to determine which specific users accessed records — rendering audit logs useless.

Source: HHS OCR

Montefiore Medical Center

February 2024

$4.75M

Employee stole ePHI of 12,517 patients over six months and sold it to an identity theft ring. Breach only discovered in 2015 when NYPD informed the hospital — not through the hospital's own monitoring.

Source: HHS OCR

Excellus Health Plan

January 2021

$5.1M

Hackers infiltrated systems and remained undetected for approximately 17 months, compromising ePHI of 9.3 million individuals. 17-month dwell time directly attributable to absence of system activity monitoring.

Source: HHS OCR

Blackbaud

October 2023 / May 2024

$56.25M

Largest multistate healthcare-related settlement. 2020 data breach affected thousands of nonprofit institutions including healthcare organizations. Blackbaud learned of breach May 14, 2020 but didn't disclose until July 16. Required to implement third-party compliance assessments for seven years.

Source: NY Attorney General

What went wrong in every case

The same audit trail failures appear across every healthcare enforcement action, from small clinics to the nation's largest health plans.

  • No functioning audit trails — the most common HIPAA citation across all cases
  • Shared credentials destroyed auditability — impossible to track individual access
  • Insider threats undetected for months — only caught when police called, not monitoring
  • Breach dwell times measured in months and years — 17-month and 9-month intrusions
  • Delayed breach disclosure — months between discovery and notification

How tamper-proof evidence changes the equation

Cryptographic audit trails make it mathematically impossible to alter or destroy records without detection.

Every Access is Recorded

Cryptographic receipts capture each access event at the moment it occurs. Insider theft becomes detectable in real-time because every data access has an immutable, timestamped record — not just a log entry that can be deleted.

Shared Credentials Don't Hide Activity

ATL receipts are tied to specific events regardless of the authentication layer. Even when credentials are shared, the cryptographic chain records what happened and when — making individual access patterns traceable.

Dwell Time Drops to Zero

Chain consistency verification means unauthorized access patterns are detectable immediately, not months later. The 17-month dwell times and 6-month insider thefts become impossible when the audit trail is continuously verifiable.

Ready to make your audit trail tamper-proof?

Create your free account and start protecting your data with cryptographic evidence that can't be altered or destroyed.