The U.S. Department of Health and Human Services’ Office for Civil Rights (HHS OCR) on Jan. 15 fined Excellus Health Plan $5.1 million and ordered it to implement a corrective action plan for failures relating to a 2015 data breach that exposed the personal information of 9.3 million individuals.

Jaclyn Jaeger is a freelance contributor to Compliance Week after working for the company for 15 years. She writes on a wide variety of topics, including ethics and compliance, risk management, legal,...