A healthcare organization does not have to be a major hospital system to face serious regulatory consequences. A home-care agency can face multimillion-dollar exposure over payroll, Medicaid and compliance certifications. A small physician practice can face a federal HIPAA investigation after ransomware exposes weaknesses that existed long before the attack.
Two documented New York enforcement cases illustrate how quickly routine business functions can become regulatory matters, and why healthcare organizations should examine compliance before regulators do.
For this article, AABEAT.TV has chosen not to emphasize the names of the organizations involved. The cases are based on publicly available government enforcement records, which are linked as primary sources below.
Case one: home care — when payroll became a multimillion-dollar compliance problem
In September 2024, federal and New York authorities announced settlement agreements involving two related Brooklyn-based licensed home care services agencies. According to the U.S. Department of Justice, the government investigated whether the agencies complied with New York's Wage Parity Act while receiving Medicaid reimbursement for home-care services.
The issue was much larger than an ordinary payroll dispute. Under New York's Wage Parity requirements, certain home-care aides providing Medicaid-funded services must receive required minimum levels of wages and benefits. The government alleged that the agencies certified compliance and sought and received Medicaid reimbursement even though investigators determined that payments to certain aides fell below required compensation levels.
That connection changed the nature of the problem. A compensation issue became a Medicaid reimbursement issue. And a Medicaid reimbursement issue became a False Claims Act matter.
The financial consequences. Under the settlement agreements announced by the Justice Department, the two agencies agreed to pay $3.9 million to the federal government and $5.85 million to New York State to resolve the government's fraud claims involving conduct from 2012 through 2022, for a total of $9.75 million. The agencies were also required to pay $7.5 million to current and former home-care aides entitled to compensation under the Wage Parity Act. Combined, the announced financial obligations were approximately $17.25 million.
The Justice Department also reported that the agencies admitted to conduct that led the government to determine they had fallen short of Wage Parity Act requirements.
Official source: U.S. Department of Justice, Eastern District of New York, September 30, 2024. View the official DOJ enforcement announcement.
The lesson for home-care agencies. The important lesson is not simply that a company paid millions of dollars. It's how different compliance obligations became connected. A home-care organization may treat payroll as an HR responsibility, Medicaid reimbursement as a billing function, licensing as a compliance matter, cybersecurity as an IT issue, and marketing as something else entirely. But regulators do not necessarily view these functions in isolation. If an organization certifies that certain conditions are satisfied in order to receive government reimbursement, it needs evidence supporting those certifications.
Home-care executives should be asking whether aides are being compensated according to current federal, state and local requirements; whether payroll records can prove it; whether representations made to Medicaid are consistent with actual operating practices; who independently validates those representations; whether policies match what actually happens; and whether supporting evidence can be retrieved quickly if regulators ask. A policy saying an organization complies with a requirement is not the same thing as evidence demonstrating compliance.
Case two: physician practice — ransomware was the incident, the missing risk analysis became the compliance problem
The second case involved a much smaller healthcare organization. In April 2025, the U.S. Department of Health and Human Services Office for Civil Rights announced a settlement involving a small New York neurology practice following a ransomware investigation.
According to HHS, the practice reported that ransomware encrypted its IT network and made electronic protected health information inaccessible. Approximately 6,800 individuals may have been affected. The potentially compromised information included patient names, clinical information, health-insurance information, demographic information, Social Security numbers, driver's-license information and state identification information.
An important distinction should be understood: the regulatory problem was not simply that the practice suffered a cyberattack. Healthcare organizations can be attacked even when security measures exist. OCR's investigation instead focused on a fundamental HIPAA Security Rule requirement. HHS reported that investigators found the practice had failed to conduct an accurate and thorough risk analysis to determine potential risks and vulnerabilities to the confidentiality, integrity and availability of its electronic protected health information.
The settlement: $25,000 and two years of monitoring. The physician practice agreed to pay $25,000 and implement a corrective action plan monitored by OCR for two years. According to HHS, corrective measures included conducting an accurate and thorough risk analysis, developing a risk-management plan, reviewing and revising HIPAA policies where necessary, and training workforce members.
Official source: U.S. Department of Health and Human Services, Office for Civil Rights, April 25, 2025. View the official HHS/OCR enforcement announcement.
Why this matters to small physician practices. There is a dangerous assumption in healthcare cybersecurity: "we are too small to be a target." HIPAA does not create an exemption because an organization has only a few physicians. A small practice may still maintain electronic health records, insurance information, patient demographics, Social Security numbers, diagnostic information, lab results, prescriptions, billing information and copies of identification documents. That information has value, and the responsibility to protect electronic protected health information does not disappear because the practice is small.
The critical issue is not simply whether a practice has antivirus software. The better questions are: when was the last documented HIPAA Security Risk Analysis, what vulnerabilities were identified, and what was done about them? Where is electronic patient information stored, and who has access, including former employees? Are backups protected and tested, and could ransomware encrypt backups along with production systems? How would physicians continue treating patients if the EHR became unavailable tomorrow morning, how long could the practice operate manually, and when was that process last tested? These questions extend beyond cybersecurity into operational resilience.
Two different businesses, two different regulations, the same governance problem
The two enforcement matters are very different. The home-care case involved employee compensation, Medicaid reimbursement and False Claims Act allegations. The physician-practice case involved ransomware and a HIPAA Security Rule risk-analysis requirement. But they reveal a common weakness: organizations often believe something is being done without maintaining sufficient evidence that it is actually being done.
A written cybersecurity policy does not prove that a risk assessment occurred. A payroll policy does not prove that compensation was calculated correctly. A HIPAA manual does not prove employees were properly trained. A backup does not prove information can be restored. A disaster-recovery plan does not prove the organization can continue providing healthcare services during an outage. And a website saying an organization is "compliant" certainly does not establish compliance.
Your website may also be a compliance document
Healthcare leaders should also remember that regulators, competitors, attorneys, patients and members of the public can see what an organization publishes online. A healthcare website may contain statements involving licensing (what services the organization claims it is authorized to provide), training and certifications it advertises, patient testimonials that disclose names, photographs, diagnoses or treatment experiences, descriptions of government programs such as Medicare, Medicaid or CDPAP, advertising claims like "#1," "best" or "most trusted" that need to be substantiated, the organization's privacy practices around patient information, and whether patients with disabilities can reasonably access important information and digital services.
For regulated healthcare organizations, the website should not be treated merely as a marketing brochure. It is a public representation of the organization.
Five questions healthcare leaders should ask today
Whether an organization operates a home-care agency, physician practice, clinic or another healthcare business, leadership should be able to answer five fundamental questions:
- What regulations actually apply to us? Not what is assumed to apply, but what requirements govern licenses, workforce, reimbursement, patient information, vendors, locations and technology.
- What are we representing to regulators and payers? What certifications, attestations and claims are being made to Medicaid, Medicare, insurers, state regulators and other organizations.
- What evidence proves those representations are accurate? If challenged tomorrow, could the organization produce it.
- What could stop our critical healthcare services? Ransomware, a cloud outage, loss of the EHR, a payroll problem, a third-party vendor failure, a telecommunications failure, or loss of key personnel.
- Have we actually tested our ability to continue and recover? A recovery-time estimate is an expectation. A successful test provides evidence. Those are not the same thing.
The question is not whether you have a compliance manual
The deeper question is whether an organization can demonstrate that its controls are working. One case resulted in approximately $17.25 million in combined settlement and worker-payment obligations. Another resulted in a $25,000 HIPAA settlement and two years of federal monitoring after a ransomware investigation. The dollar amounts are dramatically different. The management lesson is remarkably similar: compliance must be operational, measurable and supported by evidence.
Healthcare organizations should discover weaknesses themselves, before an attacker, employee, patient, whistleblower, auditor or regulator discovers them first.
If a regulator walked into an organization tomorrow and asked for evidence that its critical compliance and cybersecurity controls are actually working, how long would it take leadership to answer? Minutes, hours, days, or would someone need to find the policy first and schedule a meeting? That answer may say more about an organization's regulatory resilience than the policy itself.
Official government sources
Home-care enforcement example: U.S. Department of Justice, U.S. Attorney's Office for the Eastern District of New York, September 30, 2024, "Brooklyn-Based Home Health Care Agencies Settle Fraud Claims for $9.75 Million and Agree to Pay $7.5 Million in Wages and Benefits to Underpaid Aides."
Physician-practice enforcement example: U.S. Department of Health and Human Services, Office for Civil Rights, April 25, 2025, "HHS Office for Civil Rights Settles HIPAA Ransomware Cybersecurity Investigation with Neurology Practice."
Editorial & legal note: AABEAT.TV has intentionally focused this article on the compliance lessons rather than the identities of the healthcare organizations involved. The underlying organizations are identifiable through the cited public government records. The home-care matter involved settlement agreements addressing government allegations and admitted conduct described by the Department of Justice; this article does not characterize every allegation as an independent judicial finding. The physician-practice matter was described by HHS as a settlement concerning a potential HIPAA Security Rule violation; settlement does not, by itself, constitute an adjudication of liability. This article relies on publicly available government information and is presented for news, educational and informational purposes. It is not legal, regulatory, cybersecurity or financial advice.

