Utopia Tech
Healthcare4 min read

Shen Smiles Pays $140,000 to Resolve HIPAA Privacy Rule Violations

Dr. Linda L. Shen, the owner and operator of Shen Smiles, a Pennsylvania dental practice, has agreed to pay a financial penalty of $140,000 to the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) to resolve alleged HIPAA Privacy Rule violations. This is the 56 th enforcement action under OCR’s Right of Access enforcement initiative to result in a fina

UT

Utopia Tech

October 9, 2026 · 4 min read

Share

Dr. Linda L. Shen, the owner and operator of Shen Smiles, a Pennsylvania dental practice, has agreed to pay a financial penalty of $140,000 to the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) to resolve alleged HIPAA Privacy Rule violations.

This is the 56 th enforcement action under OCR’s Right of Access enforcement initiative to result in a financial penalty. On April 21, 2020, OCR received a complaint from a patient’s attorney alleging that multiple requests had been sent to Shen Smiles requesting a copy of the patient’s medical records, but they had not been provided. OCR informed Shen Smiles about the complaint on May 20, 2020, and of OCR’s intention to initiate an investigation.

OCR subsequently issued a data request, requiring documentation such as the practice’s policies and procedures regarding patient requests for access to their protected health information (PHI). Shen Smiles responded via its attorney, objecting to the data request. The case was escalated, and the HHS’s Regional Office of General Counsel (OGC) issued a letter requesting the data be provided to OCR.

The documentation was not provided; however, Dr. Shen submitted an affidavit stating that the requested documents did not exist at the practice as they had been stolen by a workforce member. OCR re-requested documentation related to the Right of Access complaint, and in response to the reported theft, requested documentation related to compliance with the administrative safeguards of the HIPAA Privacy Rule regarding uses and disclosures of PHI.

OCR also requested the practice’s breach notification policies and procedures, and copies of any breach notifications issued in response to the theft incident. Dr. Shen responded, providing a “None” response to the additional documentation requests.

Get The FREE HIPAA Compliance Checklist Immediate Delivery of Checklist Link To Your Email Address Please enable JavaScript in your browser to complete this form. Business Email * Name * First Last Number * Company Name * Get Free Checklist Please Enter Correct Email Address Your Privacy Respected HIPAA Journal Privacy Policy Based on the inability to provide evidence of compliance with 45 C.

F. R. §§ 164.

530(c), 164. 502(a), and 164. 404-408 of the HIPAA Privacy Rule, OCR determined that Shen Smiles had failed to comply with these HIPAA requirements.

During the course of the investigation, OCR learned that physical patient records were not maintained in good order at the practice and had not been properly secured in locked cabinets, or otherwise secured against unauthorized uses and disclosures. Patient files were stored in unsecured locations, including clear plastic boxes in the hygienist’s office, on the floor, and in boxes in a private bathroom, and were often carried between office locations and Dr.

Shen’s home. When patients arrived for appointments, their records often could not be located Dr. Shen stated that she believed that the patient’s records had been illegally taken by a former office manager.

She informed OCR that the employee had not been reprimanded or disciplined, and no action had been taken to prevent similar incidents in the future. She also confirmed that employees had not been given formal HIPAA training on the HIPAA Privacy Rule. OCR informed Shen Smiles of the findings of the investigation and offered to settle the alleged HIPAA Privacy Rule violations informally.

The offer was declined, and OCR was notified that evidence would be submitted to support a waiver of a civil monetary penalty. OCR determined that the information submitted did not support a waiver of a civil monetary penalty. OCR obtained permission from the U.

S. Attorney General to impose a civil monetary penalty for violations of 45 C. F.

R. § 164. 530(i)(1) – the implementation of policies and procedures – and 45 C.

F. R. § 164.

530(c)(2)(i) – a lack of administrative safeguards. OCR determined that the violations fell into the category of reasonable cause, rather than willful neglect, and calculated a maximum penalty of $1,400,000, comprising $700,000 for each violation. Since Shen Smiles is a small, rural healthcare provider, OCR determined that the maximum fine may jeopardize the ability of the practice to operate, and applied a 90% reduction on covered entity size alone.

Shen Smiles requested a hearing before an administrative law judge; however, prior to that hearing, the matter was resolved with a resolution agreement that included the $140,000 financial penalty. This was OCR’s 11 th HIPAA case this year to be resolved with a financial penalty, and its second resolved enforcement action of the year under its HIPAA Right of Access enforcement initiative.

As of October 9, 2026, OCR has collected $3,170,250 in penalties from its 2026 HIPAA enforcement activities . The post Shen Smiles Pays $140,000 to Resolve HIPAA Privacy Rule Violations appeared first on The HIPAA Journal .

Originally published at hipaajournal.com

Share
▸ Want a deeper look?

Talk to an architect about applying this to your stack.

60-minute technical evaluation, no obligation. We'll map the ideas in this article to your environment.

Skip to main content