Illinois-based OSF Healthcare System and its affiliated covered entities have agreed to pay $552,250 as part of an agreement with the U.S. Department of Health and Human Services’ Office for Civil Rights (HHS OCR) to resolve potential violations of the Health Insurance Portability and Accountability Act (HIPAA) Privacy, Security, and Breach Notification Rules. The resolution brings with it a list of compliance lessons for all covered health care entities.

Jaclyn Jaeger is a freelance contributor to Compliance Week after working for the company for 15 years. She writes on a wide variety of topics, including ethics and compliance, risk management, legal,...