Dental Practice Fined $350,000 for HIPAA Violations

January 8, 2025
A woman is sitting in a dental chair and giving a thumbs up.

OVerview

In December 2024, Westend Dental, an Indianapolis-based dental practice, agreed to pay a $350,000 penalty to the Indiana Attorney General's Office to resolve multiple alleged violations of federal and state laws, including the Health Insurance Portability and Accountability Act (HIPAA)1

Background

The investigation began after a patient complained about being unable to obtain their dental records. It was discovered that Westend Dental had experienced a ransomware attack by the Medusa Locker group on or around October 20, 2020, which compromised patients' protected health information (PHI). The practice failed to report the breach promptly, only notifying the Indiana Attorney General's Office on October 28, 2022—more than two years later—and initially denied that a ransomware attack had occurred. 

Violations

The Indiana Attorney General's Office identified several violations, including:

  • Failure to Comply with the HIPAA Breach Notification Rule: Westend Dental did not notify affected patients within the required 60-day period following the discovery of the breach. 
  • Failure to Comply with the HIPAA Security Rule: The practice lacked adequate administrative, physical, and technical safeguards to protect PHI. 
  • Failure to Comply with the HIPAA Privacy Rule: Unauthorized disclosures of PHI occurred, and there was a lack of proper notices of privacy practices.
  • Violations of Indiana State Laws: The practice failed to implement reasonable procedures and provide timely breach notifications as required by state law. 

Settlement and Corrective Actions

As part of the settlement, Westend Dental agreed to:

  • Pay a $350,000 financial penalty.
  • Implement a corrective action plan to ensure compliance with HIPAA and state laws.
  • Notify all individuals who were patients as of November 23, 2023, about the breach.
  • In the United States, data breaches have been found to cost between $140 to $160 per compromised record in 20231. This figure encompasses various expenses, including detection, notification, and post-breach response efforts, but does not include the 24 month credit monitoring cost of $240 to $720 per individual2.

Lessons Learned

The Westend Dental case underscores the importance of proactive and comprehensive measures to protect sensitive patient information. Healthcare organizations must integrate the following practices to prevent similar incidents:

  • Maintaining a Comprehensive Data Registry: A well-organized data registry ensures that organizations can identify where sensitive patient data is stored, who has access, and how it is used. This visibility is critical for identifying vulnerabilities and ensuring compliance with HIPAA and privacy standards.
  • Implementing Secure, Offsite Backups: Regularly backing up data to secure, offsite locations provides a safety net against ransomware attacks and accidental data loss. Offsite backups should be encrypted and routinely tested to ensure they can be restored effectively during emergencies.
  • Deploying Advanced Antivirus and Anti-Malware Solutions with Zero Trust: While robust antivirus and anti-malware tools are essential for identifying and mitigating threats, organizations should also implement a Zero Trust security model. This model assumes no entity—inside or outside the network—is trusted by default. It requires continuous verification of all users and devices attempting to access systems, minimizing potential attack surfaces.
  • Strengthening Incident Response Plans with Training: A detailed and regularly tested incident response plan is vital. It should outline steps for containment, investigation, recovery, and notification. Furthermore, incident response training for all employees, particularly those involved in security and compliance, ensures that the team can act swiftly and effectively during a breach.
  • Annual Reviews and Updates to the System Security Plan: HIPAA requires organizations to annually review and update their system security plans. This ensures that policies, safeguards, and procedures remain effective against evolving threats. Regular updates should incorporate lessons learned from incidents, emerging technologies, and regulatory changes.
  • Engaging in Regular Security Audits and Penetration Tests: Conducting routine security audits and penetration tests helps identify gaps in security protocols. Audits ensure compliance with the latest regulations and provide a roadmap for addressing vulnerabilities. Audits should be performed at least annually with quarterly (or monthly) penetration testing.
  • Obtaining Correct Insurance Coverage and Ensure Compliance with Requirements: Cybersecurity insurance and breach liability coverage are essential for mitigating the financial impact of data breaches. These policies can help cover the costs of breach notifications, credit monitoring, legal fees, and other associated expenses. These policies should be reviewed annually with both your insurance agent and your IT provider to ensure that you have the right coverage and that your internal policies and procedures are following the policy requirements. The last thing you want is to have an incident, only to find out that your insurance will not cover it because you did not comply with the insurance requirements.

By adopting these practices, healthcare providers can mitigate risks, ensure regulatory compliance, and strengthen their defenses against the ever-evolving landscape of cyber threats.

A woman is sitting at a desk in a warehouse using a cell phone.
February 28, 2025
Cyberattacks are a growing concern, and small to mid-sized businesses – especially dental, medical, accounting, and construction offices – are increasingly targeted. To help organizations respond effectively to security incidents, a free Security Incident Response Toolkit is now available.
A man in a suit and tie is holding a globe with the words cyber security written on it.
February 26, 2025
As cyber threats continue to grow, the FBI is warning businesses—particularly small and mid-sized dental, medical, accounting, and construction offices—to back up their data immediately. This alert comes in response to a surge in attacks specifically targeting these industries.
February 7, 2025
As of October 14, 2025, Microsoft will officially end support for Windows 10. After this date, the operating system will no longer receive security updates, technical assistance, or software updates from Microsoft. While your Windows 10 PC will continue to function, using an unsupported operating system poses significant risks.
A man is using a laptop computer with a loading bar on the screen.
February 5, 2025
Microsoft’s ESU program provides critical security updates for Windows 10 devices beyond the official end-of-support date. This is a paid service designed for individuals and businesses that need extra time to transition to a supported operating system.
A woman is sitting in a dental chair and giving a thumbs up.
November 4, 2024
The cloud has the ability to change the game for your dental practice, especially if you're have or are interested in branching out to multiple locations.
A man is smiling while sitting in a dental chair.
October 28, 2024
Let’s put you in the perspective of a patient stepping into a dental office: what’s the first thing you notice? Maybe it’s how modern and clean the space looks or how quickly you can get connected to their Wi-Fi. Or perhaps it's the opposite, and you find yourself in a place that seems to have taken a time machine back to the '90s, complete with outdated computers and a spotty internet connection.
By Anastasia Ippolito October 18, 2024
Let's talk about something that may not get a ton of attention during your workday but is extremely important and always looming in the background - HIPAA compliance.
A dentist is talking to a patient in a dental chair.
October 15, 2024
Want to integrate or upgrade any of the technology we’ve covered in this blog but don’t know where to start? That’s where we come in! We’re experts who specialize in the dental industry and know how to upgrade your practice without disrupting it.
September 19, 2024
In 2014, 4GB to 8GB of RAM was generally considered sufficient for most business operations. Standard tasks like document management, light multitasking, and simple software applications could easily run on 4GB, with 8GB being recommended for more intensive use. This was especially true in professions such as legal, dental, and healthcare, where electronic record systems and case management software were just beginning to integrate more advanced features. However, as software became more sophisticated and cloud computing started playing a central role, the demand for memory grew. Legal professionals now rely on cloud-based management systems, AI-powered document analysis, and e-discovery tools, which all require more RAM for efficient functioning. Similarly, the medical profession witnessed the proliferation of complex EHR systems, AI diagnostics, and telemedicine solutions, pushing the baseline RAM requirement to 16GB in most offices.
A man is using a tablet computer with a pen.
September 17, 2024
CDK Global serves thousands of dealerships across the country, providing essential services such as dealer management systems, CRM tools, and digital marketing solutions.
More Posts
Share by: