Cadia Healthcare, a company operating five nursing homes and rehabilitation facilities in Delaware, was fined $182,000 by the U.S. Department of Health and Human Services' Office for Civil Rights (HHS OCR) for violating HIPAA regulations. The violation stemmed from a 'Success Stories' marketing campaign in which Cadia Healthcare posted photos and names of patients on social media platforms without obtaining proper authorization. The campaign was intended to highlight patient recoveries and positive outcomes, but it resulted in the impermissible disclosure of protected health information (PHI) for approximately 150 patients. The HHS OCR investigation was initiated after a complaint was filed in September 2021, alleging that Cadia had posted a complainant's photo, name, and details about their medical conditions, treatment, and recovery on its website. The investigation confirmed that a Cadia employee had posted the complainant's information as part of the campaign without securing a signed authorization. Regulators determined that these actions constituted a clear breach of HIPAA privacy rules, which require explicit patient consent before sharing PHI for marketing or publicity purposes. The fine imposed reflects the seriousness of the violation and the number of individuals affected. Cadia Healthcare operates multiple facilities providing skilled nursing, rehabilitation, and long-term care, making the scope of the breach significant within the healthcare sector. The case underscores the importance of strict adherence to privacy regulations when handling patient information, especially in the context of marketing and social media. HHS OCR emphasized that healthcare organizations must implement robust policies and training to prevent unauthorized disclosures of PHI. The incident serves as a warning to other healthcare providers about the risks of using patient information in promotional materials without proper consent. The regulatory response included not only the financial penalty but also requirements for Cadia to improve its privacy practices and staff training. The breach highlights ongoing challenges in balancing patient privacy with organizational marketing efforts in the digital age. Healthcare entities are reminded that even well-intentioned campaigns can result in significant regulatory and reputational consequences if privacy laws are not strictly followed. The case also demonstrates the effectiveness of the complaint process in bringing privacy violations to the attention of regulators. Cadia Healthcare's experience is likely to prompt other organizations to review their own policies regarding the use of patient information online. The incident reinforces the critical need for healthcare providers to obtain explicit, documented consent before sharing any patient-related content publicly.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
The Dutch Data Protection Authority imposed a €182,000 fine on a nursing home for unlawfully posting patient photos online, indicating a privacy violation involving residents' personal data. The references do not provide a more specific event date beyond the publication date.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.