Top of the World Ranch Treatment Center Settles HIPAA Security Rule Violation

by | Feb 22, 2026

Top of the World Ranch Treatment Center (TWRTC) paid $103,000 to the U.S. Department of Health and Human Services’ Office for Civil Rights to settled a potential HIPAA Security Rule violation and will implement required corrective actions.

HIPAA Security Rule Violation Identified

OCR determined that Top of the World Ranch Treatment Center, an Illinois substance use disorder treatment provider, did not conduct an accurate and thorough risk analysis as required under the HIPAA Security Rule’s administrative safeguard provisions. Covered entities and business associates need to conduct this safety measure to protect the integrity, confidentiality, and availability of electronic protected health information (ePHI).

Breach Report and Investigation Trigger

OCR investigated TWRTC after receiving a breach report filed in March 2023. The breach report indicated that a successful phishing attack enabled unauthorized access to electronic protected health information (ePHI) through a workforce member’s email account. The report indicated that the breach affected the ePHI of 1,980 patients.

OCR Enforcement Initiative and Settlement Terms

The settlement is the 11th enforcement action under OCR’s risk analysis initiative addressing alleged failures to comply with the risk analysis requirement of the HIPAA Security Rule. TWRTC agreed to pay a $103,000 financial penalty to resolve the investigation. The resolution agreement also requires TWRTC to implement a corrective action plan under the supervision of OCR for two years.

Corrective Action Requirements

The corrective action plan requires the covered entity to conduct and complete a documented risk analysis that accurately assesses the risks to the confidentiality, integrity, and availability of its ePHI. The provider must develop and implement a risk management plan to address and mitigate risks and vulnerabilities identified in the risk analysis. Written policies and procedures that comply with the HIPAA Security Rule, HIPAA Privacy Rule, and HIPAA Breach Notification Rule must be maintained and updated as necessary. Workforce members with access to ePHI must receive annual HIPAA training on the updated policies and procedures.

OCR Director Paula M. Stannard remarked that compliance with this HIPAA Security Rule is essential for protecting ePHI and addressing cybersecurity threats. OCR’s official settlement announcement outlines additional measures that covered entities and business associates may implement to address or prevent cyber-threats, including identifying where ePHI is located in an organization, conducting periodic risk analyses, and ensuring appropriate audit controls and authentication mechanisms.

Raise the level of HIPAA Awareness in your organization with Learner-Friendly, Comprehensive and Affordable HIPAA Training.

COMPREHENSIVE HIPAA TRAINING

Ryan Coyne

Ryan Coyne is a results-driven leader in the healthcare compliance industry, specializing in regulatory compliance, compliance training, and assisting healthcare organizations and business associates in achieving and maintaining compliance. With a deep knowledge of healthcare regulations and a keen understanding of the challenges faced by the industry, Ryan has developed a reputation as a trusted advisor and advocate for ethical and compliant practices in healthcare. Ryan has successfully advised and guided numerous healthcare organizations, business associates, and healthcare professionals on achieving and maintaining compliance with regulatory training requirements. Ryan's professional focus is using his in-depth expertise and leading a world class team of subject matter experts at ComplianceJunction in regulatory compliance to help organisations navigate the complex landscape of ensuring staff adhere to healthcare regulations. You can connect with Ryan via LinkedIn and follow on Twitter

Raise the level of HIPAA Awareness in your organization with Learner-Friendly, Comprehensive and Affordable HIPAA Training.

Comprehensive HIPAA Training

Used in 1000+ Healthcare Organizations and 100+ Universities

    Full Course - Immediate Access

    Privacy Policy