What Happened
In December 2020, a ransomware attack hit Comprehensive Neurology, PC, a neurology practice in New York. The attack encrypted the practice’s IT network and its electronic protected health information, locking staff out of the very systems they needed to run the office. The exposed data included patient names, clinical information, health insurance details, demographic information, Social Security numbers, and driver’s license numbers, the kind of information that follows a patient around for years, not months.
The practice reported the breach, and the HHS Office for Civil Rights (OCR), the federal agency that enforces HIPAA, opened an investigation. What OCR found wasn’t that the practice had ignored some obscure technical requirement. It was more basic than that: Comprehensive had never conducted an accurate and thorough risk analysis to identify potential risks and vulnerabilities to the confidentiality, integrity, and availability of the patient data it held. That’s not a suggestion buried in HIPAA’s fine print. It’s one of the foundational, required steps of the Security Rule, the starting point every other safeguard is supposed to build on.
In April 2025, OCR announced a settlement: Comprehensive Neurology agreed to pay $25,000 and to operate under a two-year, monitored corrective action plan. That plan requires the practice to actually conduct the risk analysis it had skipped, build a risk management plan to address what that analysis turns up, revise its written HIPAA policies and procedures, and put its staff through HIPAA training tied to their actual job duties. OCR noted this was its 12th ransomware-related enforcement action and the 8th under its Risk Analysis Initiative, a specific enforcement push aimed squarely at practices that never did this foundational work.
What stands out about this case is its scale. This isn’t a hospital network or a national health plan; it’s a single neurology practice, the kind of operation that might have a handful of providers and a small office staff. The fine itself, $25,000, is modest as these things go. But the two-year federal monitoring period, the legal exposure, and the operational disruption of a ransomware attack in the first place are not modest at all for a practice that size.
Why This Matters If You’re Not a Big Company
It’s tempting to read HIPAA enforcement news and assume it only applies to organizations with compliance departments and general counsel on retainer. This case says otherwise. OCR didn’t single out Comprehensive Neurology because it was large or high-profile; it’s neither. It got flagged because a breach happened, and when regulators looked underneath it, there was no risk analysis to point to. That’s a gap that exists at plenty of small medical, dental, and healthcare practices right now, not because anyone is being careless, but because a formal risk analysis often just never makes it onto the to-do list of a busy front office.
The same logic extends past healthcare. Any small business holding sensitive customer data, health records, financial information, personal identifiers, is one incident away from the same kind of scrutiny this practice faced. You don’t need to be a target of interest to attackers to get hit; ransomware operators are largely opportunistic, and a small practice’s systems are often easier to break into than a large hospital’s. The fine here is a reminder that “we didn’t know we were vulnerable” is not a defense once regulators start asking what you did to find out.
What Actually Would Have Stopped This
A risk analysis isn’t a technical audit that requires an in-house IT department to perform. It’s a documented process: inventory where patient or customer data lives, identify what could go wrong with it, unpatched software, unsegmented networks, weak backup practices, missing multi-factor authentication, and write down what you’re doing about each risk you find. HIPAA has required this for years, and OCR’s Risk Analysis Initiative exists specifically because so many practices, especially small ones, still haven’t done it.
Beyond the paperwork, the practical safeguards that follow from a real risk analysis are the ones that actually blunt a ransomware attack: offline or immutable backups that a network-wide encryption event can’t reach, multi-factor authentication on remote access and email, and a patched, monitored network that limits how far an attacker can move once they’re in. None of that requires enterprise budget. It requires doing the assessment first, so you know what to fix.
Security Checklist for Your Business
Conduct a documented risk analysis. Identify where sensitive data lives, what could compromise it, and put your findings in writing, not just in your head.
Keep offline or immutable backups. A ransomware attack that encrypts your live network shouldn’t be able to touch your recovery copy too.
Require MFA on remote access and email. This closes one of the most common doors ransomware operators use to get in.
Train staff on their specific HIPAA duties. Generic annual training slides don’t stick the way role-specific guidance does.
A $25,000 fine and two years of federal monitoring started with a step that costs far less than either: writing down where the risks actually are. MSP Today’s trusted tech partner is JK Computer Solutions. If you want a second set of eyes on your setup, get in touch.



