HIPAA Security Rule update

    Insights · OCR Enforcement Lessons

    What a $140,000 Dental Settlement Says About the File Behind the Chart (2026)

    An OCR enforcement lesson from the October 8, 2026 Shen Smiles resolution agreement. A records complaint opened the case. The $140,000 settlement covers missing evidence of Privacy Rule policies (45 CFR 164.530(i)) and safeguards (45 CFR 164.530(c)(2)(i)).

    Jim Johnson · Founder and president

    8 October 2026 · 10 min read

    The short version

    On October 8, 2026, HHS' Office for Civil Rights (OCR) announced a $140,000 settlement with Dr. Linda Shen d/b/a Shen Smiles, P.C., a solo dental practice in Drums, Pennsylvania. The complaint that opened the case, on April 21, 2020, alleged the practice did not provide a former patient with access to that person's protected health information after multiple requests. The potential violations the agreement actually resolves are two administrative duties: no evidence of policies and procedures for the Privacy Rule and the Breach Notification Rule (45 CFR 164.530(i)), and no evidence of reasonable safeguards (45 CFR 164.530(c)(2)(i)). The agreement is not an admission of liability. (Source: HHS resolution agreement, published October 8, 2026.)

    On April 21, 2020, the lawyer for a former patient filed a complaint with OCR. The complaint alleged the practice had not provided that person's protected health information after multiple requests. On May 20, 2020, OCR wrote the practice, said it intended to investigate, and issued data requests.

    Six years later, the practice agreed to pay $140,000.

    OCR's post on October 8 describes that complaint, and it stops there: a Pennsylvania dental provider, a timely-access allegation, $140,000. (Source: OCR on X, October 8, 2026.) Read the resolution agreement posted the same day and the case changes shape. The complaint got OCR in the door. The settlement prices the file the practice could not produce once OCR was inside.

    What OCR actually settled

    Shen Smiles is a one-dentist professional corporation. Dr. Linda Shen is the sole owner. The practice submits claims electronically, including to Pennsylvania Medicaid, and it creates and keeps patient information. That is why the agreement treats it as a covered entity under 45 CFR 160.103. (Source: resolution agreement, factual background.)

    OCR's investigation, as the agreement recounts it, found two things in the narrative before it ever lists a violation. Patient records were not properly maintained. Employees had not been given formal HIPAA Privacy Rule training.

    The potential violations the agreement names as the covered conduct are narrower, and they are written as evidence problems:

    • The practice failed to produce evidence that it had implemented policies and procedures for the Privacy Rule and the Breach Notification Rule, as 45 CFR 164.530(i) requires.
    • The practice failed to produce evidence that it had reasonably safeguarded protected health information from intentional or unintentional use or disclosure that would violate the Privacy Rule, as 45 CFR 164.530(c)(2)(i) requires.

    Sit with that phrase. "Failed to produce evidence." OCR did not need a dramatic breach narrative. It asked for evidence of the policies, and for evidence of the safeguards. The agreement says the practice produced neither.

    A Notice of Proposed Determination on July 31, 2024 used the stronger formulation. OCR proposed a civil money penalty of $140,000 for a failure to implement those policies and procedures (45 CFR 164.530(i)(1)) and a failure to reasonably safeguard protected health information (45 CFR 164.530(c)(2)(i)), at the reasonable cause penalty tier. Reasonable cause means the covered entity knew, or by exercising reasonable diligence would have known, that the act or omission violated the rule, and did not act with willful neglect (45 CFR 160.401). Willful neglect is the higher tier: conscious, intentional failure, or reckless indifference. The agreement does not show the per-violation math. The dollar caps for each tier are inflation-adjusted every year and published at 45 CFR part 102, so the base figures in 45 CFR 160.404 are not the current dollar amounts. What the agreement states is the tier and the proposed amount: $140,000.

    The chart request is a real duty. It is not what this agreement prices.

    The right of access is still the rule a complaint like this one invokes. An individual has a right to inspect and obtain a copy of protected health information in a designated record set (45 CFR 164.524(a)(1)). The practice must act on that request no later than 30 days after it receives it (45 CFR 164.524(b)(2)(i)). It may take one extension of no more than 30 days, and only if, inside the original 30 days, it sends a written statement of the reasons for the delay and the date it will finish (45 CFR 164.524(b)(2)(ii)).

    This agreement does not list 45 CFR 164.524 in the covered conduct. It does not say the practice missed the 30-day clock, and it does not say the practice met it. The complaint alleged that access was not provided after multiple requests. The potential violations OCR carried through a proposed penalty, an appeal, and a settlement are the policy section and the safeguard section.

    That distinction is the lesson. A patient who cannot get the chart is how these cases start. A practice that cannot hand over its policies is how this one was priced. OCR's public list titles the matter a Privacy Rule investigation, not a Right of Access investigation. (Source: HHS resolution agreements, October 8, 2026.)

    Small scales the design. It does not remove the duty.

    The policy standard is written for a one-dentist office as well as a hospital. A covered entity must implement policies and procedures designed to comply with the Privacy Rule and the Breach Notification Rule. Those policies "must be reasonably designed, taking into account the size and the type of activities that relate to protected health information undertaken by a covered entity" (45 CFR 164.530(i)(1)). Size changes how elaborate the procedures need to be. It does not excuse the absence of a written set you can produce. The same section says the standard is not to be read as permission to violate any other requirement.

    The safeguard duty in this case is the Privacy Rule duty, not the Security Rule's technical checklist. A covered entity must have appropriate administrative, technical, and physical safeguards to protect the privacy of protected health information (45 CFR 164.530(c)(1)), and it must reasonably safeguard that information from any use or disclosure that violates the Privacy Rule (45 CFR 164.530(c)(2)(i)). Separately, the agreement says OCR learned that the practice's patient records were not properly maintained. The agreement does not define what "not properly maintained" means. It does put that finding in the same narrative as a safeguard case. A record you cannot account for is a hard thing to show as safeguarded.

    Training sits beside those findings, and it is worth keeping in its own box. The Privacy Rule requires a covered entity to train workforce members on the policies and procedures, as necessary and appropriate for their functions, and to document that the training happened (45 CFR 164.530(b)(1) and (b)(2)(ii)). The agreement says OCR determined this practice had not given employees formal Privacy Rule training. That determination is in the factual background. It is not one of the two potential violations in the covered conduct. Do not read the $140,000 as a training fine. Do read it as a reminder that training is a standard you have to meet, and that OCR writes down what it does not find.

    The dollar amount did not move

    OCR told the practice the results of the investigation on November 27, 2023, and by mail the next day. On January 3, 2024, it sent a Letter of Opportunity. That letter is the chance to submit mitigating factors (45 CFR 160.408), affirmative defenses (45 CFR 160.410), or support for a waiver (45 CFR 160.412) before a penalty is proposed. The practice responded on February 6, 2024. OCR later wrote that the response did not support an affirmative defense or a waiver.

    The proposed penalty was $140,000. On November 8, 2024, the practice appealed to the Departmental Appeals Board, Docket No. C-25-108. The resolution agreement ends that appeal and HHS transaction number 20-380382. The resolution amount is $140,000, due in one lump sum. Paragraph 3 of the agreement says it is not an admission of liability.

    The published agreement does not attach a corrective action plan. Many OCR settlements do, often with two years of monitoring. This one resolves the proposed penalty and the appeal by payment. The release covers the covered conduct on or before November 27, 2023. It does not cover anything else. Like other OCR resolution agreements, it also says the release does not extend to a criminal action under 42 U.S.C. § 1320d-6. The agreement does not say any criminal case exists.

    The practical read is simple. From the 2020 data request to the 2024 letter to the appeal, the number OCR proposed is the number in the settlement. The moment that changes the outcome is earlier: the day you can produce the file.

    What would have changed the outcome

    Not a better argument in 2024. A file in 2020.

    Policies and procedures for the Privacy Rule and the Breach Notification Rule, in written or electronic form, kept for six years from creation or from the last date they were in effect, whichever is later (45 CFR 164.530(i) and 164.530(j)). Evidence that protected health information is reasonably safeguarded (45 CFR 164.530(c)), and an answer for how the records are maintained, because that is what OCR wrote down here. A training record for the people who handle those records and who answer a request for them (45 CFR 164.530(b)).

    A binder no one can find on the day of the data request does not answer "produce evidence." The Security Rule has its own six-year documentation rule, at 45 CFR 164.316. We wrote about what that record has to look like when OCR asks. This case is the Privacy Rule version of the same habit. The ransomware settlements keep turning up a missing risk analysis. This one turned up a policy file the practice could not produce. The trigger changes. The question OCR asks first is still whether you can show the work.

    If a patient asks for the chart tomorrow, answer it on the clock in 45 CFR 164.524. If OCR asks for the policies the day after, the chart response will not be the document they are scoring.

    Where this leaves a small practice

    You do not need a hospital's policy manual. You need the set 164.530(i) describes, designed for the size of the work you actually do, and you need to be able to hand it over. Live Compliance keeps the policies, the training record, and the evidence in one place, so a data request has an answer that already exists. If you want to see where you stand, the free 12-minute gap scan gives you a score and the specifics. In sixteen years of this work, our audit success rate is 100 percent. The file was built before anyone asked for it.

    Accuracy & legal note. This article summarizes a public HHS Office for Civil Rights resolution agreement published October 8, 2026, alongside Privacy Rule requirements in 45 CFR Part 164 and enforcement provisions in 45 CFR Part 160, accurate as of the date below. The agreement is a settlement of potential violations. It is not an admission of liability and it is not a court finding. Details are drawn from the agreement itself: ocr-resolution-agreement-shen-smiles.pdf. OCR's public post describes the complaint and the dollar amount: x.com/hhsocr/status/2108256113452036163. This is general educational information, not legal advice. Verify current requirements at hhs.gov/hipaa or with your compliance counsel. Last updated: October 8, 2026.

    Jim Johnson, Founder and president, Live Compliance

    Jim Johnson

    Founder and president, Live Compliance

    Jim has run HIPAA programs for 500+ healthcare organizations since 2010. He writes about the compliance work practices actually face: the Privacy and Security Rules, OSHA, and what an auditor asks for.

    About the founder

    New pieces by email

    The next piece, when it is published, and nothing else.

    Unsubscribe any time. Nothing here needs an email to read.

    See where your program stands before an auditor does.

    Get your free 10-minute audit-readiness score. Then, if you want it, the guarantee: audit-ready in 60 days, or we keep working at no additional cost until you are.

    Or talk to a specialist

    ~10 minutes · No credit card · No call required

    500+
    healthcare organizations
    100%
    audit success rate
    2010
    protecting healthcare since