Ambry Genetics is a large clinical genomics lab, not a small practice, but the three Security Rule findings OCR cited are the same three items a 5-person clinic can be cited for. The event that opened the door was a single phishing email: one workforce member's mailbox was compromised in January 2020, and PHI for 225,370 people was potentially exfiltrated, including names, dates of birth, Social Security numbers, financial data, diagnoses, lab results, and treatment information. A small practice with a shared inbox and one clicked link is exposed on exactly the same theory.

Read past the headline number and the three specific failures are what matter. OCR cited Ambry for no accurate and thorough risk analysis, no procedures for terminating access to ePHI when a workforce member leaves, and no unique user identifier for people accessing systems that hold ePHI. Every small practice has all three of these obligations. If your risk analysis is a template you last touched two years ago, if a departing hygienist or front-desk hire still has an active login a month after they left, or if the whole front desk shares one EHR account, those are the exact items OCR is looking at.

The corrective action plan translates cleanly to small-practice work. Ambry has to run a fresh risk analysis, write a risk management plan against what it finds, revise its Security Rule policies, put unique user IDs in place across every system that holds ePHI, and train workforce members on those policies. A 1 to 20 person clinic can build the same evidence trail without a two-year OCR-monitored plan hanging over it, and the shortest path is to check each of those items in your own office this week.

Settlement amount
$700,000
Corrective action
Two-year corrective action plan
Individuals affected
225,370
Resolution date
September 17, 2026

What to check in your practice