North Country Communications
  • about
  • services
  • resources
  • contact
  • Menu Menu
  • about
  • Team
  • services
  • resources
  • contact
  • Home

OCR’s 54th HIPAA Right of Access Enforcement Action: What Healthcare Providers Should Learn from the Concentra Settlement

December 19, 2025

By Rachel Klugman Seeger, Founder and Principal, North Country Communications

The HHS Office for Civil Rights (OCR) has quietly announced its 54th settlement under the HIPAA Right of Access Enforcement Initiative, reinforcing once again that timely access to medical records is not optional. It is a core patient right and a foundational requirement of the HIPAA Privacy Rule.

This latest settlement involves Concentra, Inc., a major occupational health services provider headquartered in Texas. OCR’s investigation found that Concentra failed to provide an individual with access to their protected health information (PHI) within the required 30‑day timeframe. Instead, the individual waited 399 days for their records.

Some may recall that this is Concentra’s second enforcement action with OCR. The first, announced in 2014, involved a stolen laptop containing unsecured electronic PHI and resulted in a $1.7 million settlement and a robust corrective action plan. While the earlier case centered on Security Rule failures, this new action highlights a different but equally critical compliance obligation: honoring patients’ right to access their own health information.

What Happened in the Latest Case

OCR’s investigation revealed several key issues:

  • The individual’s initial request for access went unfulfilled for more than a year.
  • Concentra’s business associate issued an invoice for $82.57 for the records — a fee the individual disputed.
  • Months later, the business associate reduced the fee to $6.50 and finally mailed the paper records on March 21, 2019.

OCR and Concentra ultimately resolved the matter before an administrative hearing. Concentra agreed to pay $112,500. Learn more in the Notice of Proposed Determination and Settlement Agreement:

  • Notice of Proposed Determination: https://www.hhs.gov/sites/default/files/ocr-concentra-npd.pdf
  • Settlement Agreement: https://www.hhs.gov/sites/default/files/ocr-concentra-settlement-agreement.pdf

As OCR Director Paula Stannard emphasized in the agency’s December 16, 2025, press release, “Individuals should not have to make multiple requests and file a complaint with OCR to gain access to their health information.”

Why This Matters, Even When Only One Patient Is Affected

This case underscores a pattern we continue to see across OCR’s Right of Access Initiative: Even isolated failures can trigger enforcement.

The size of the organization doesn’t matter. The number of affected individuals doesn’t matter. What matters is whether a patient’s lawful request for their own medical records is honored promptly, at a reasonable, cost‑based fee, and without unnecessary barriers.

What Providers Should Do Now

Healthcare organizations — from small practices to national systems — should take this as a reminder to:

  • Review and update their HIPAA Right of Access policies and procedures
  • Audit turnaround times for access requests
  • Standardize reasonable, cost‑based fees
  • Ensure business associates follow your access requirements
  • Train staff on patient rights and escalation pathways

The legal fees, operational disruption, and regulatory scrutiny simply aren’t worth the risk. More importantly, honoring access rights is central to patient trust. Want to learn more about how we can help bolster your Right of Access processes in your organization? Schedule your free, confidential 30‑minute consultation today at North Country Communications.

https://northcountrycommunications.com/wp-content/uploads/2025/11/NCC-Logo-black-space-2.png 0 0 rachelS https://northcountrycommunications.com/wp-content/uploads/2025/11/NCC-Logo-black-space-2.png rachelS2025-12-19 12:27:532025-12-19 13:22:31OCR’s 54th HIPAA Right of Access Enforcement Action: What Healthcare Providers Should Learn from the Concentra Settlement

Blogs

  • A Major Privacy Change Has Arrived for Healthcare Organizations — Are You Prepared?April 1, 2026 - 8:24 pm
  • When AI Meets Healthcare Without Safeguards: An Alleged Breach and What It Reveals About Patient TrustJanuary 27, 2026 - 4:32 pm
  • When Breaches Repeat: Why Due Diligence and Good Faith Compliance Matter More Than EverJanuary 8, 2026 - 6:53 pm
  • OCR’s 54th HIPAA Right of Access Enforcement Action: What Healthcare Providers Should Learn from the Concentra SettlementDecember 19, 2025 - 12:27 pm
  • Why a Holding Statement Matters When a Healthcare Organization Experiences a HIPAA BreachDecember 15, 2025 - 9:30 am

Press Releases

  • Understanding the 2026 Part 2 Shift: A Practical Briefing to Prepare Your Team for February 16, 2026January 16, 2026 - 2:36 pm
  • Former Federal Healthcare Leaders Launch North Country Communications to Guide HIPAA Breach ResponseDecember 15, 2025 - 9:00 am
North Country Communications Logo
(518) 290-1230
(877) NORTH-20

info@northcountrycommunications.com

© 2026 - North Country Communications, LLC
  • Link to LinkedIn
Scroll to top Scroll to top Scroll to top

This site uses cookies. By continuing to browse the site, you are agreeing to our use of cookies.

Accept settings

Cookie and Privacy Settings



How we use cookies

We may request cookies to be set on your device. We use cookies to let us know when you visit our websites, how you interact with us, to enrich your user experience, and to customize your relationship with our website.

Click on the different category headings to find out more. You can also change some of your preferences. Note that blocking some types of cookies may impact your experience on our websites and the services we are able to offer.

Essential Website Cookies

These cookies are strictly necessary to provide you with services available through our website and to use some of its features.

Because these cookies are strictly necessary to deliver the website, refusing them will have impact how our site functions. You always can block or delete cookies by changing your browser settings and force blocking all cookies on this website. But this will always prompt you to accept/refuse cookies when revisiting our site.

We fully respect if you want to refuse cookies but to avoid asking you again and again kindly allow us to store a cookie for that. You are free to opt out any time or opt in for other cookies to get a better experience. If you refuse cookies we will remove all set cookies in our domain.

We provide you with a list of stored cookies on your computer in our domain so you can check what we stored. Due to security reasons we are not able to show or modify cookies from other domains. You can check these in your browser security settings.

Other external services

We also use different external services like Google Webfonts, Google Maps, and external Video providers. Since these providers may collect personal data like your IP address we allow you to block them here. Please be aware that this might heavily reduce the functionality and appearance of our site. Changes will take effect once you reload the page.

Google Webfont Settings:

Google Map Settings:

Google reCaptcha Settings:

Vimeo and Youtube video embeds:

Privacy Policy

You can read about our cookies and privacy settings in detail on our Privacy Policy Page.