- State
- UT
- Covered entity type
- Healthcare Provider
- Individuals affected
- 500
- Business associate present
- No
- Type of breach
- Improper Disposal
- Location of breached information
- Network Server
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
Steven A. Porter, M.D., a gastroenterologist in Ogden, Utah, has agreed to pay $100,000 to the Office for Civil Rights (OCR) at the U.S. Department of Health and Human Services (HHS) and to adopt a corrective action plan to settle a potential violation of the Health Insurance Portability and Accountability Act (HIPAA) Security Rule.
OCR began investigating Dr. Porter’s medical practice (the Practice) after it filed a breach report with OCR in 2013. OCR’s investigation revealed the Practice’s ongoing noncompliance with the Security Rule’s Security Management Process standard, including the Practice’s failure to conduct enterprise-wide risk analyses, and its failure to reduce the risks and vulnerabilities to a reasonable and appropriate level. OCR also determined that the Practice lacked sufficient HIPAA policies and procedures. Despite OCR’s provision of technical assistance regarding the Practice’s risk analysis and risk management efforts, the Practice failed to conduct Security Rule compliant risk analyses and risk management plans.
In addition to the monetary settlement, the Practice will undertake a corrective action plan that includes two years of monitoring.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.