◆ Metropolitan Community Health Services in North Carolina, doing business as Agape Health Services, has agreed to pay $25,000 to settle potential violations of the HIPAA Security Rule, the HHS Office for Civil Rights (OCR) said July 23.[1] Metro, a federally qualified health center, serves an underserved population in rural North Carolina, which OCR considered in reaching the settlement. It stemmed from a June 9, 2011, breach report filed by Metro about the impermissible disclosure of protected health information to an unknown email account, affecting 1,263 patients. “OCR’s investigation revealed longstanding, systemic noncompliance with the HIPAA Security Rule. Specifically, Metro failed to conduct any risk analyses, failed to implement any HIPAA Security Rule policies and procedures, and neglected to provide workforce members with security awareness training until 2016,” OCR said. Metro didn’t admit liability in the settlement.