Fined for not looking: three 2025 HIPAA penalties, one risk analysis requirement

Warby Parker, Health Fitness and Northeast Radiology had three different breaches, and the regulator cited the same HIPAA Security Rule requirement each time. This guide gives you a worked risk-analysis entry for each case, the AWS WAF controls that answer it, and a blank worksheet for your own systems.

  • $1.5M

    Largest of the three penalties

  • 3 years

    About how long one exposure ran before it was found

  • 1

    Requirement cited in all three cases

Get the guide

Free PDF, 15 pages. Published October 2026 by safeINIT, an AWS Advanced Tier Services Partner.

Fined for not looking: three 2025 HIPAA enforcement actions and the AWS WAF controls that answer them, guide cover

Three 2025 HIPAA enforcement actions, one citation

They weren't fined for being breached. They were fined for not looking. Three companies, three different attacks, and the HHS Office for Civil Rights cited the same HIPAA Security Rule requirement in all three: risk analysis.

  • Warby Parker

    Credential stuffing

    $1.5M

    Civil money penalty, announced February 2025

    Attackers replayed usernames and passwords stolen in unrelated breaches against customer accounts. 197,986 people were affected, and the data included eyewear prescriptions.

    The AWS answer

    AWS WAF Account Takeover Prevention on the login path.

    Source: HHS Office for Civil Rights
  • Health Fitness Corporation

    Web crawlers

    $227,816

    Settlement, announced March 2025

    A software misconfiguration left ePHI on a server discoverable on the internet and exposed to automated crawlers from 2015 until it was found in 2018. No attacker was needed.

    The AWS answer

    Access control first, then AWS WAF Bot Control at the edge.

    Source: HHS Office for Civil Rights
  • Northeast Radiology

    Imaging server breach

    $350,000

    Settlement, announced April 2025

    Unauthorized individuals accessed radiology images on a PACS server between April 2019 and January 2020. The practice notified 298,532 patients.

    The AWS answer

    AWS WAF IP sets, geo rules and rate-based rules at the edge, with network rules for non-HTTP imaging traffic.

    Source: HHS Office for Civil Rights

45 C.F.R. 164.308(a)(1)(ii)(A)Risk analysis

Three attacks. One citation. Read the requirement in the eCFR

Written from a live session with AWS

Cosmin Drimba, CEO and co-founder of safeINIT, presented the three cases in September 2026. Radu Dobrinescu, Senior Partner Solutions Architect at AWS, walked through the AWS WAF configuration for each one in the console. The recording is below, and the slides are on the event page.

See the session slides

What's inside: worked risk-analysis entries and the AWS WAF configuration

A green dashboard is not proof of compliance. The compliance officer owns the HIPAA obligation, the auditor owns the evidence, and the engineer owns the AWS console. Each does their job correctly, and the breach happens between them. The guide is written for all three to read.

  1. The cases, with sources

    What happened, what the regulator cited, what it cost

    Each case follows the same pattern: the attack, the data involved and how long it went on, then the requirement the regulator said was not met. Sources are listed with each case.

  2. The paperwork

    What the risk analysis should have said

    For each case, a worked example of one risk-analysis entry: threat, likelihood, impact, current control, residual risk and planned safeguard. An example of one entry, not a full assessment.

  3. The console

    The AWS WAF configuration behind each safeguard

    Account Takeover Prevention, Bot Control and edge access rules: how each one works, what it does not cover, and how to roll it out in Count mode before you switch to Block.

  4. Your turn

    A blank worksheet for your own environment

    The same six fields from every case, empty. Fill in one entry per system that holds ePHI and you have the start of the analysis an auditor asks for.

Preview · 1 / 4
Overview page: a security tool is not a compliance requirement, with the three 2025 enforcement actions at a glance
Worked risk-analysis entry for the credential stuffing case: threat, likelihood, impact, current control, residual risk and planned safeguard
One requirement, three times: the three penalties connected to the risk analysis citation, 45 C.F.R. 164.308(a)(1)(ii)(A)
Blank risk-analysis worksheet with six fields: threat, likelihood, impact, current control, residual risk and planned safeguard
Get the guide

Get the HIPAA enforcement guide

The three cases, a worked risk-analysis entry for each, the AWS WAF configuration, and the blank worksheet.

All fields are required.

We email the guide to this address. We also send occasional follow-ups about HIPAA on AWS; unsubscribe anytime. See the Privacy Policy.

Frequently asked questions

Common questions about the guide and how we handle your details.

Teams that run electronic protected health information (ePHI) on AWS and have an auditor to answer to: compliance officers, engineering leads and the people who sit between them. It applies to covered entities and to business associates. One of the three cases is a business associate. For the control-by-control mapping of the Security Rule to AWS, see the HIPAA on AWS guide.

Want to know where you stand?

The free assessment scores your AWS setup and sends the results to you by email. Look before someone else does.