Fined for not looking
Three 2025 HIPAA penalties and the AWS WAF controls that answer them
A webinar with AWS on three 2025 HIPAA enforcement cases. Three different attacks, one violated control, and the AWS WAF configuration that answers each one. Recorded live on September 16, 2026.
Slides from the session
About this talk
Where healthcare teams get breached, then fined for the same incident
A security tool and a compliance requirement are not the same thing, and the gap between the two is where healthcare companies get breached and then fined for the same incident. We walked through three enforcement cases from the US health regulator, all announced in 2025: three companies, three completely different attacks, with penalties from $227,816 to $1.5 million. One detail is identical in all three cases, and the session builds up to it.
Cosmin Drimba, CEO and co-founder of safeINIT, presented the cases. Radu Dobrinescu, Senior Partner Solutions Architect at AWS, took the console side: the AWS WAF configuration that answers each one, walked through live. Both stayed for questions at the end.
The session is for teams running ePHI on AWS with an auditor to answer to. The recording, the slides and the written guide are all on this page.
Key takeaways
Every number and regulation on a slide, with the source next to it.
The cases
- Three real 2025 enforcement actions, from breach to penalty
- What the regulator actually cited each company for
- What the paperwork should have said, entry by entry
The AWS side
- What HIPAA actually asks for, and what a control is
- The AWS WAF capability that answers each case, live in the console
- The evidence an auditor asks for, and where it comes from
Want to know where you stand?
The free assessment scores your AWS setup and sends the results to you by email. Look before someone else does.























