WebinarVirtualSeptember 202630 mins + Q&A

Fined for not looking

A webinar with AWS on three 2025 HIPAA enforcement cases. Three different attacks, one violated control, and the AWS WAF configuration that answers each one. Recorded live on September 16, 2026.

Slide · 1 / 23
Title slide: Fined for not looking, three HIPAA penalties and the AWS WAF controls that answer them, with Cosmin Drîmbă (CEO and co-founder, safeINIT) and Radu Dobrinescu (Senior Partner Solutions Architect, AWS)
Agenda: three jobs, three people, one gap; what HIPAA actually requires; what a control is; three breaches, one violated control; operating and proving it
The breach happens in the seams: the compliance officer owns the HIPAA obligation, the auditor owns the evidence, the engineer owns the AWS console
HIPAA's Security Rule: it applies when you hold ePHI, requires safeguards for confidentiality, integrity and availability, and is outcome-based rather than a product checklist. HIPAA never says buy tool X; it says assess your risk and address it
A control is a required safeguard with a citation: risk analysis 164.308(a)(1)(ii)(A), risk management 164.308(a)(1)(ii)(B), activity review 164.308(a)(1)(ii)(D)
Section divider: same control, three attacks, three AWS answers
Case one: $1.5M HIPAA penalty, Warby Parker, February 2025. Credential stuffing against the login page, 197,986 people affected, prescription data is ePHI. Source: HHS Office for Civil Rights
What OCR actually cited in case one: 45 C.F.R. 164.308(a)(1)(ii)(A), risk analysis, a failure to conduct an accurate and thorough assessment of the risks to ePHI, plus risk management and activity review
What the analysis should have said for case one: an illustrative risk analysis entry for the member login endpoint. Threat: credential stuffing. Likelihood and impact high. Current control: signature-based managed rule groups. Planned safeguard: AWS WAF Account Takeover Prevention on the login path
AWS WAF Account Takeover Prevention: checks submitted credentials against a leaked-credential database, inspects login responses for failure patterns, scoped to the login endpoint by default
Case two: $227,816 settlement, Health Fitness Corporation, March 2025. ePHI exposed to web crawlers through a server misconfiguration, undetected for about three years, a business associate under HIPAA. Source: HHS Office for Civil Rights
What OCR actually cited in case two: the same risk analysis control, 45 C.F.R. 164.308(a)(1)(ii)(A), as in case one
What the analysis should have said for case two: an illustrative risk analysis entry for an internet-exposed content server. Threat: unauthorized retrieval of ePHI by automated crawlers. Current control: none specific to bot traffic. Planned safeguard: AWS WAF Bot Control on endpoints serving ePHI
AWS WAF Bot Control: detects unverified crawlers, scrapers and scripted clients through behavioral fingerprinting and token-reuse signals; allows verified search crawlers and blocks or rate-limits the rest
Case three: $350,000 settlement, Northeast Radiology, April 2025. An unsecured PACS imaging server reachable from the internet, 298,532 patients notified, about ten months of undetected access. Source: HHS Office for Civil Rights
What OCR actually cited in case three: the same risk analysis control, 45 C.F.R. 164.308(a)(1)(ii)(A), a third time
What the analysis should have said for case three: an illustrative risk analysis entry for an internet-reachable PACS imaging server. Threat: direct access by unauthorized parties. Current control: none restricting reachability. Planned safeguard: AWS WAF with geo and IP allow-listing and rate-based rules
AWS WAF edge access control: geo and IP allow-listing so only approved networks reach the endpoint, rate-based rules that throttle scanning and abuse, Firewall Manager pushing the same policy to every account
One control, three times: $1.5M Warby Parker, $227,816 Health Fitness, $350,000 Northeast Radiology, all cited under 164.308(a)(1)(ii)(A). The tool stops the attack; the risk analysis is what the auditor asks for
The third control, where the tool produces evidence: WAF logs in S3 and CloudWatch, Security Hub, human review, rule tuning. Tuning feeds back into the rules; the loop is the control
Three languages, one team: the control (risk analysis and safeguards), the evidence (logging and review that holds up in an audit), and the AWS configuration (ATP, Bot Control, edge access) operated inside safeZONE
Want to know where you stand? Take the free security assessment at safeinit.com/assessment-score
Closing slide: safeINIT and AWS, questions

About this talk

Where healthcare teams get breached, then fined for the same incident

A security tool and a compliance requirement are not the same thing, and the gap between the two is where healthcare companies get breached and then fined for the same incident. We walked through three enforcement cases from the US health regulator, all announced in 2025: three companies, three completely different attacks, with penalties from $227,816 to $1.5 million. One detail is identical in all three cases, and the session builds up to it.

Cosmin Drimba, CEO and co-founder of safeINIT, presented the cases. Radu Dobrinescu, Senior Partner Solutions Architect at AWS, took the console side: the AWS WAF configuration that answers each one, walked through live. Both stayed for questions at the end.

The session is for teams running ePHI on AWS with an auditor to answer to. Registrants receive the recording and slides by email.

Key takeaways

Every number and regulation on a slide, with the source next to it.

The cases

  • Three real 2025 enforcement actions, from breach to penalty
  • What the regulator actually cited each company for
  • What the paperwork should have said, entry by entry

The AWS side

  • What HIPAA actually asks for, and what a control is
  • The AWS WAF capability that answers each case, live in the console
  • The evidence an auditor asks for, and where it comes from

Bring this kind of work to your AWS environment.

If something here lined up with what you're building, the next step is a working call with the team that delivered it.