Shen Smiles, a dental practice, has agreed to pay $140,000 to resolve alleged HIPAA Privacy Rule violations. The settlement highlights failures to provide patients with timely access to their medical records. Covered entities must review their patient access policies to avoid similar enforcement actions.
On October 9, 2026, the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) announced that Shen Smiles, a dental practice, agreed to pay $140,000 to resolve alleged violations of the HIPAA Privacy Rule. The settlement stems from a complaint alleging that the practice failed to provide a patient with timely access to their protected health information (PHI).
Under the HIPAA Privacy Rule, covered entities are required to provide individuals with access to their medical records within 30 calendar days of a written request, with one 30-day extension permitted under limited circumstances. The OCR investigation found that Shen Smiles failed to meet these requirements, resulting in an unreasonable delay in providing the requested records.
The resolution agreement also requires Shen Smiles to implement a corrective action plan, which includes updating policies and procedures related to patient access rights, training workforce members on those policies, and reporting compliance to OCR for a specified monitoring period.
This enforcement action directly affects Shen Smiles, a dental practice, and its patients. However, the broader implication extends to all HIPAA-covered entities, including dental practices, physician offices, hospitals, health plans, and business associates. The settlement serves as a reminder that patient access rights under the HIPAA Privacy Rule are actively enforced, and small practices are not exempt from scrutiny.
Patients across the healthcare system benefit from this enforcement action, as it reinforces their right to access their own health information in a timely manner. When patients cannot access their records promptly, they may face delays in receiving follow-up care, transferring to new providers, or making informed decisions about their health.
The Shen Smiles settlement underscores several important compliance lessons for healthcare organizations:
The HIPAA Right of Access Initiative, launched by OCR in 2019, has been a significant enforcement focus. This settlement is one of many that demonstrate OCR's commitment to holding covered entities accountable for failing to provide timely access to PHI. Since the initiative began, OCR has announced dozens of settlements totaling millions of dollars in penalties.
The HIPAA Privacy Rule requires covered entities to act on a patient's request for access within 30 calendar days. Any delay beyond this timeframe, without a valid extension, can constitute a violation. In this case, the practice's failure to meet this deadline triggered the enforcement action.
Many HIPAA enforcement actions involve large health systems, but this settlement demonstrates that small and mid-sized practices are also subject to OCR scrutiny. Dental practices, in particular, may have less mature compliance programs, increasing their vulnerability.
Beyond the $140,000 settlement payment, Shen Smiles must implement a corrective action plan. This includes policy updates, workforce training, and periodic reporting to OCR. The administrative burden and ongoing monitoring costs can significantly exceed the monetary penalty.
Healthcare organizations should take the following steps to reduce their risk of similar enforcement actions:
Review existing policies and procedures for handling patient requests for medical records. Ensure they comply with the HIPAA Privacy Rule's requirements, including the 30-day response deadline, fee limitations, and permissible format requirements.
Provide regular training to all workforce members on patient access rights. Front-desk staff, medical records personnel, and clinicians should understand their roles and responsibilities when a patient requests their records.
Establish systems to track patient access requests from receipt to fulfillment. This helps ensure timely responses and provides documentation in the event of an OCR investigation.
Regularly audit patient access workflows to identify bottlenecks and delays. Address any issues promptly to prevent recurring violations.
If OCR initiates an investigation, respond promptly and cooperatively. Demonstrating good faith and a willingness to correct issues can influence the outcome.
The Shen Smiles settlement serves as a clear reminder that HIPAA patient access rights are not optional. Covered entities of all sizes must prioritize timely access to PHI and maintain robust compliance programs. Failure to do so can result in significant financial penalties and corrective action obligations that extend far beyond the initial settlement.
The HIPAA Privacy Rule requires covered entities to provide patients with access to their protected health information within 30 calendar days of a written request. One 30-day extension is permitted if the entity provides a written explanation for the delay.
Shen Smiles agreed to pay $140,000 to the Office for Civil Rights to resolve alleged HIPAA Privacy Rule violations related to delayed patient access to medical records.
The HIPAA Right of Access Initiative is an OCR enforcement priority launched in 2019 that focuses on ensuring patients can access their health records in a timely manner and at a reasonable cost. It has resulted in dozens of settlements and millions of dollars in penalties.
Yes, dental practices are covered entities under HIPAA and are subject to the same enforcement actions as other healthcare providers. The Shen Smiles settlement demonstrates that OCR actively pursues violations at dental practices and other small healthcare organizations.
If a healthcare provider fails to provide timely access to your medical records, you can file a complaint with the HHS Office for Civil Rights through its online complaint portal. OCR investigates complaints and has taken enforcement actions against providers that violate patient access rights.
PoliWriter creates all the policies and documentation you need for compliance, customized to your organization. AI-powered, audit-ready, hours not months.
Get Started Free