Part 1 of 2: We revisit where OCR’s HIPAA Right of Access enforcement began and what enforcement action #1 still teaches healthcare providers today.
Seven years ago this month, an $85,000 settlement launched OCR’s HIPAA Right of Access enforcement initiative. 55 enforcement actions later, the compliance lesson remains remarkably familiar.
In 2019, then OCR Director Roger Severino made the agency’s position clear: providing patients access to their health information isn’t simply good healthcare it is required by law.
On September 9, 2019, the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) announced its first enforcement action and settlement under the HIPAA Right of Access Initiative.
Bayfront Health St. Petersburg agreed to pay $85,000 and enter a corrective action plan after OCR investigated a complaint involving a mother seeking prenatal health records concerning her unborn child.
Almost exactly seven years later, OCR has reached #55. Looking back at where the initiative started reveals how much and how little has changed.
According to OCR, a mother requested access to health information from Bayfront Health St. Petersburg. After she filed a complaint, OCR opened an investigation.
The requested health information was eventually provided more than nine months after the initial request. HIPAA generally required the provider to act on the request within 30 days.
The case also highlighted that HIPAA access rights can extend beyond patients requesting their own records. They can apply to parents seeking medical information concerning their minor children and, in this case, a mother seeking prenatal health records concerning her child.
Bayfront agreed to a $85,000 settlement and one year of OCR monitoring.
Technology available to healthcare providers has changed significantly since 2019.
The underlying compliance problem hasn’t.
In August 2026, OCR announced its 55th HIPAA Right of Access enforcement action, involving Azul Vision, Inc.
A patient requested access to her protected health information (PHI) in January 2023. She did not receive her records until nearly two years later and only after OCR began investigating.
Azul Vision agreed to pay $50,000 and two years of monitoring by OCR.
Consider the two cases:
#01 Bayfront: More than nine months to provide the requested health information.
#55 Azul Vision: Nearly twenty-four months to provide the requested health information.
Almost seven years and 54 additional enforcement actions separate the cases. Yet the basic compliance issue is remarkably similar: a patient requested access to health information and did not receive it within the required timeframe.
For a smaller healthcare practice, a Right of Access failure doesn’t necessarily begin with someone deliberately ignoring HIPAA.
It can be much simpler.
A request arrives. An employee forwards an email. Someone assumes another person is handling it. The request gets buried among everyday responsibilities.
Meanwhile, the compliance clock keeps moving.
Can your practice answer these questions today?
If those answers aren’t readily available, the weakness may be in the process rather than the people.
Tools such as uRISQ’s Data Subject Access Request module can help provide a structured way to manage, assign, document and track requests through completion.
Seven years ago, OCR’s first Right of Access enforcement action sent healthcare providers a clear message: patients have a right to timely access to their medical records.
Fifty-five enforcement actions later, the message hasn’t changed.
What has changed is the technology available to manage these requests. Healthcare providers have more tools to replace disconnected emails, spreadsheets and manual follow-up with documented processes that track requests from receipt through completion.
Seven years and 55 enforcement actions later, are healthcare providers getting the message?
| Cookie | Duration | Description |
|---|---|---|
| cookielawinfo-checbox-analytics | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics". |
| cookielawinfo-checbox-functional | 11 months | The cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional". |
| cookielawinfo-checbox-others | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other. |
| cookielawinfo-checkbox-necessary | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary". |
| cookielawinfo-checkbox-performance | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance". |
| viewed_cookie_policy | 11 months | The cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data. |

