Author: Colington Consulting

  • More Big Penalties for HIPAA Violations as the Year Comes to End

    Huge fines for HIPAA violations are making the news once again. And these are some doozies. The Office for Civil Rights (OCR) are two for two this time – Texas Health and Human Services Commission (TX HHSC) was hit for $1.6 million, and University of Rochester Medical Center (URMC) for $3 million.

    Large penalties like these are certainly newsworthy and further outline the seriousness of HIPAA noncompliance. Hereโ€™s what happened with both organizations and why itโ€™s such a big deal.

    TX HHSC HIPAA Violations – $1.6 Million Fine

    An investigation found that a division of TX HHSC had a data breach that enabled unauthorized users to view the electronically protected health information (ePHI) of 6,617 people. According to a press release from the Office for Civil Rights, the information exposed included names, addresses, social security numbers and treatment information.

    The OCR found that in addition to the data breach, TX HHSC failed to conduct an enterprise-wide security risk analysis, failed to implement access and audit controls on the information technology system, and was unable to determine how many people accessed the ePHI while it was publicly accessible.

    Although the OCR provided TX HHSC with the opportunity to provide โ€œwritten evidence of mitigating factors or affirmative defenses and/or written evidence in support of a waiver of a CMP within thirty (30) days from the date of the receipt of the letter,โ€ TX HHSC did not respond.

    OCR Director Roger Severino stated – and quite correctly – โ€œNo one should have to worry about their private health information being discoverable through a Google search.โ€

    URMC HIPAA Violations – $3 Million Fine

    In this case, the OCR imposed the fine on the University of Rochester Medical Center in response to multiple instances of the health system failing to encrypt mobile devices. This lack of encryption resulted in a breach of patients’ protected health information more than once. In one example, it was an unencrypted laptop that was lost. In two others, it was a lost flash drive.

    OCR’s investigation into the incidents found that URMC had โ€œneglected to utilize device controls and employ encryption for electronic protected health information,โ€ among other security measures. The health system had also failed to conduct a systemwide risk analysis. (In case you havenโ€™t noticed a pattern yet, performing said risk analysis is a big deal, and should be taken seriously.)

    In addition to the $3 million settlement, the URMC will also be forced to implement a corrective action plan which includes HHS monitoring the health system’s compliance with HIPAA for two years.

    How Can Your Organization Avoid Potential Penalties and Settlements?

    In about 95% of the cases when breaches are reported, OCR resolves non-compliance issues with technical guidance. However, organizations subject to these breach investigations must be able to demonstrate their comprehensive HIPAA compliance programs. This includes providing OCR documentation regarding policy and procedures; a copy of the most recent HIPAA Security Risk Assessment; training records; contingency/disaster recovery plans; and other records supporting a compliance program.

    Find Out if Your Organization is Meeting Regulatory Requirements

    If HIPAA compliance assistance is needed for your organization, we specialize in putting compliance programs in place or assessing your current program. We provide a full range of services that include conducting the required HIPAA Risk Assessment, writing and customizing a HIPAA Risk Management Plan (HIPAA Policies and Procedures) for your organization, and providing your entire staff annual required HIPAA Security Awareness & Privacy Training through our web-based platform.ย 

    Letโ€™s start the process with a free, initial consultation. In as little as 15 minutes, we can evaluate your current compliance program to determine if all mandatory privacy and security safeguards are in place to meet government regulations.