Healthcare Risk Management, “OCR Imposes $1.5 Million Civil Monetary Penalty,” quotes Henry Norwood, Esq., 6-1-2025
Kaufman Dolowich’s Henry Norwood weighs in on the importance of health care organizations protecting their ePHI (electronic protected health information) in an article on lessons learned from a breach involving an online retailer of prescription and non-prescription eyewear that resulted in a large civil penalty.
Mr. Norwood is quoted in the Relias Media Healthcare Risk Management article as saying: “The recent CMP levied by OCR spotlights the duty of health organizations to impose strict password requirements on members using their websites.” He explains that the “credential-stuffing strategy used relies on the habit of people using the same credentials for multiple websites.”
Read more at the full article here.