Ambry Genetics is a large clinical genomics lab, not a small practice, but the three Security Rule findings OCR cited are the same three items a 5-person clinic can be cited for. The event that opened the door was a single phishing email: one workforce member's mailbox was compromised in January 2020, and PHI for 225,370 people was potentially exfiltrated, including names, dates of birth, Social Security numbers, financial data, diagnoses, lab results, and treatment information. A small practice with a shared inbox and one clicked link is exposed on exactly the same theory.
Read past the headline number and the three specific failures are what matter. OCR cited Ambry for no accurate and thorough risk analysis, no procedures for terminating access to ePHI when a workforce member leaves, and no unique user identifier for people accessing systems that hold ePHI. Every small practice has all three of these obligations. If your risk analysis is a template you last touched two years ago, if a departing hygienist or front-desk hire still has an active login a month after they left, or if the whole front desk shares one EHR account, those are the exact items OCR is looking at.
The corrective action plan translates cleanly to small-practice work. Ambry has to run a fresh risk analysis, write a risk management plan against what it finds, revise its Security Rule policies, put unique user IDs in place across every system that holds ePHI, and train workforce members on those policies. A 1 to 20 person clinic can build the same evidence trail without a two-year OCR-monitored plan hanging over it, and the shortest path is to check each of those items in your own office this week.
- Settlement amount
- $700,000
- Corrective action
- Two-year corrective action plan
- Individuals affected
- 225,370
- Resolution date
- September 17, 2026
What to check in your practice
- Confirm you have a written HIPAA Security Rule risk analysis dated within the last 12 months that names every device, cloud service, EHR, and email account that touches ePHI, and that it has been reviewed after any material change.
- Confirm every user in your EHR, email, billing system, and any tool that touches ePHI logs in with their own unique account. No shared front-desk logins, no shared clinician accounts, no generic "reception" mailbox that anyone signs into.
- Confirm you have a written offboarding checklist that disables EHR, email, billing, VPN, remote access, and any cloud app access on the same day a workforce member (including contractors and vendors) leaves or changes role, and that someone owns running it.
- Confirm your workforce has had phishing-aware Security Rule training in the last 12 months, and that a single clicked link would not give an attacker access to unencrypted PHI, shared mailboxes, or stale accounts.