Fined for not looking
A webinar with AWS on three 2025 HIPAA enforcement cases. Three different attacks, one violated control, and the AWS WAF configuration that answers each one. Recorded live on September 16, 2026.
About this talk
Where healthcare teams get breached, then fined for the same incident
A security tool and a compliance requirement are not the same thing, and the gap between the two is where healthcare companies get breached and then fined for the same incident. We walked through three enforcement cases from the US health regulator, all announced in 2025: three companies, three completely different attacks, with penalties from $227,816 to $1.5 million. One detail is identical in all three cases, and the session builds up to it.
Cosmin Drimba, CEO and co-founder of safeINIT, presented the cases. Radu Dobrinescu, Senior Partner Solutions Architect at AWS, took the console side: the AWS WAF configuration that answers each one, walked through live. Both stayed for questions at the end.
The session is for teams running ePHI on AWS with an auditor to answer to. Registrants receive the recording and slides by email.
Key takeaways
Every number and regulation on a slide, with the source next to it.
The cases
- Three real 2025 enforcement actions, from breach to penalty
- What the regulator actually cited each company for
- What the paperwork should have said, entry by entry
The AWS side
- What HIPAA actually asks for, and what a control is
- The AWS WAF capability that answers each case, live in the console
- The evidence an auditor asks for, and where it comes from
Bring this kind of work to your AWS environment.
If something here lined up with what you're building, the next step is a working call with the team that delivered it.






















