A Pennsylvania dental practice has agreed to pay $140,000 to resolve federal allegations that it failed to hand over a patient’s records and left protected health information unsecured. The Office for Civil Rights accepted the deal with Dr. Linda L. Shen, owner of Shen Smiles, marking the 56th Right of Access case to end in a financial penalty.
The complaint reached OCR on April 21, 2020, when a patient’s attorney said repeated requests for a copy of the records had gone unanswered. When OCR opened an investigation the practice objected to the documentation request and escalated the matter to the agency’s legal counsel.
In an affidavit, Dr. Shen said the requested policy documents did not exist because a workforce member had stolen them. Asked again for right-of-access and breach-notification records, the practice answered “None.”
Investigators found physical patient files kept out of order, unsecured in clear plastic boxes, on the floor, and in boxes in a private bathroom. Records were carried between offices and the owner’s home, and patients arriving for appointments often could not have their files located.
OCR concluded the practice violated the HIPAA Privacy Rule’s safeguards and individual-access provisions, including the 45 C.F.R. sections covering uses and disclosures and breach notification duties.
Why it matters for healthcare security teams — paper records still carry enforcement risk. Locked storage, a documented right-of-access process, and responding to OCR data requests on time are the difference between a compliance fix and a six-figure settlement.