HIPAA Fines Hit Professional Services Firms
OCR's $175K settlement with BST & Co. CPAs shows business associates — including law firms handling PHI — face the same Security Rule risk-analysis duties as providers.

HIPAA Fines Hit Professional Services Firms

Shere Saidon
Shere Saidon

CEO & Founder at LlamaLab

Published July 21, 2026
7 min read
Legal Updates
Part of: Medical Record Retrieval for Law Firms

HIPAA Enforcement Reaches Accounting Firms — and the Warning for Law Firms Is Clear

The HHS Office for Civil Rights' settlement with BST & Co. CPAs — a $175,000 resolution tied to a ransomware incident and missing Security Rule risk analysis — is not a healthcare-provider story. It is a professional-services story. OCR treated an accounting firm that received electronic protected health information (ePHI) from a healthcare client as a HIPAA business associate with the same core duties as a hospital IT department.

For plaintiff law firms that ingest medical records every day, the parallel is direct: general cybersecurity is not a HIPAA risk analysis, and ransomware is now OCR's dominant large-breach pattern.

$175K

OCR settlement with BST & Co. CPAs for BA Security Rule failures

50+

Right of Access and related OCR enforcement actions completed in recent cycles

~80%

Share of large breaches tied to hacking/ransomware in recent OCR reporting

What Happened in the BST Case

OCR's investigation followed a breach report after ransomware encrypted BST systems that included ePHI from a healthcare client. According to detailed compliance analyses of the resolution, OCR concluded the firm had not conducted an enterprise-wide risk analysis covering that ePHI — the foundational Security Rule requirement under 45 CFR § 164.308(a)(1).

Without a risk analysis, a firm cannot know where ePHI lives, which systems are vulnerable, or which controls are reasonable and appropriate. OCR has repeated that finding across provider and BA settlements for years; BST shows it will not stop at traditional covered entities.

Important

The Business Associate Trigger

If a firm receives patient information while serving a healthcare client — audits, transactions, regulatory advice, or litigation support — it is likely a business associate. Plaintiff firms that receive PHI from providers under authorizations and BAAs are squarely in the handling ecosystem OCR is watching.

2026 Enforcement Context: Wider, Not Narrower

OCR's 2026 posture expands beyond Right of Access alone. Prior LlamaLab coverage tracked expanded OCR priorities and Security Rule checklist items for firms. Recent cycles also include multi-party settlement sweeps and continued emphasis on risk analysis as the most-cited deficiency.

For law firms, three enforcement themes matter most:

  1. Risk analysis documentation — not a one-page IT questionnaire
  2. Ransomware preparedness — backups, MFA, incident response, and BA oversight
  3. Vendor chain liability — retrieval platforms, cloud DMS, and AI tools that touch PHI

What OCR Expects

  • HIPAA-specific risk analysis covering ePHI systems
  • Documented safeguards: encryption, MFA, access logs
  • Executed BAAs with downstream vendors
  • Incident response plans tested against ransomware

What Does Not Count

  • Generic cyber insurance questionnaire
  • Firm-wide password policy with no ePHI inventory
  • Assuming the DMS vendor 'handles HIPAA'
  • No BAA with medical-record vendors

Practical Implications for Plaintiff Firms

Medical records are the PHI mountain

PI and mass tort practices may hold more ePHI volume than many specialty clinics — thousands of PDFs across DMS folders, email, and vendor portals. That volume is exactly why OCR's BA theory matters: the firm is a high-value ransomware target with regulated data.

Retrieval vendors need BAAs and proof

Whether firms use LlamaLab or other retrieval partners, BAAs, encryption standards, and "no training on client data" commitments should be contract requirements — not marketing footnotes.

Right of Access pressure can help and bind

OCR's Right of Access initiative pushes providers to fulfill records within 30 days, which can accelerate litigation retrieval. The same enforcement culture expects firms to secure what they receive.

Looking Ahead

Key Points

Essential takeaways from this article

Commission or update a HIPAA-specific risk analysis covering every system that stores medical records
Inventory ePHI locations: DMS, email, laptops, AI tools, and vendor portals
Execute and refresh BAAs with retrieval, hosting, and analytics vendors
Treat ransomware tabletop exercises as a compliance control, not optional IT hygiene

The Bottom Line

BST's settlement is a bright-line reminder: professional services firms that touch PHI inherit Security Rule duties. Plaintiff firms cannot outsource that responsibility to a "we use secure email" policy. The firms that treat HIPAA as an operating system — risk analysis, BAAs, encryption, vendor diligence — will survive OCR scrutiny and client security questionnaires. The firms that do not are guessing with regulated data.

Work With a HIPAA-Ready Retrieval Partner

LlamaLab retrieves medical records under BAA-backed, encrypted workflows designed for plaintiff firms — so speed does not come at the cost of Security Rule compliance.

Sources: MedComply analysis of BST CPAs settlement, HHS business associate guidance, HHS Security Rule overview, OCR Right of Access enforcement reporting. Confirm current OCR resolution texts for citation in firm policies.

Stay Updated with Latest Insights

Get the latest articles about medical record retrieval and legal tech delivered to your inbox.