Category: HIPAA Breach

  • Data Breach Costs at an All-Time High According to 2022 Report

    Guest article authored by Gabby Williams โ€“ Content Specialist at New Reach Marketing

    Data breaches have become a pervasive and costly problem in today’s digital world. With the increasing reliance on technology and the proliferation of data, the risk of data breaches has risen exponentially.

    According to the IBM Security Cost of a Data Breach Report 2022, 83% percent of organizations studied have experienced more than one data breach, and just 17% said this was their first data breach. Due to the increased occurrence of data breaches, 60% of organizations studied stated that they increased the price of their services or products.

    In this article, we will explore the rising cost of data breaches, examining the reasons behind the trend, the industry impacted the most, and the steps that can be taken to mitigate the risks.

    What Is a Data Breach?

    Data breaches refer to unauthorized access, theft, or exposure of sensitive data. This can include personal information such as names, addresses, phone numbers, Social Security numbers, financial information, and even intellectual property or trade secrets.

    Cybercriminals and hackers are constantly seeking vulnerabilities in systems and networks to gain unauthorized access and exploit sensitive data for various purposes, including financial gain, identity theft, corporate espionage, and more.

    Rising Cost of Data Breaches

    The cost of data breaches has also been on the rise in recent years, with numerous high-profile incidents grabbing headlines and affecting millions of individuals and businesses around the world.

    The IBM Report showed that the cost of a data breach averaged USD 4.35 million in 2022. This figure represents a 2.6% increase from the previous year, when the average breach cost was USD 4.24 million. Compared to 2020, the average cost has climbed 12.7% from USD 3.86 million.

    It is evident that data breaches are becoming more expensive for organizations, with the financial impact of such incidents rising each year.

    Data Breaches in Healthcare

    Healthcare organizations are particularly vulnerable to data breaches due to the wealth of personal and sensitive data stored within their systems. Patient records, medical history, insurance information, and payment details are what make them prime targets for cybercriminals seeking access to valuable data for various malicious purposes.

    Regulatory fines and legal liabilities for non-compliance with the Health Insurance Portability and Accountability Act of 1996 (HIPAA) alone are extremely costly.

    HIPAA Compliance

    All regulated entities must comply with HIPAA Privacy, Security, and Breach Notification Rules to ensure the protection and security of patient privacy and medical records. Failing to follow HIPAA safeguards greatly increases the risk of cyberattacks and results in non-compliance penalties.

    As the healthcare industry remains the primary target for data breaches, it is the responsibility of each organization, provider, and employee to maintain HIPAA compliance. Some of the most effective ways to negate data breaches and HIPAA violations include routine HIPAA compliance and cybersecurity training, penetration testing tools, and conducting required security risk assessments.

    A lack of training and assessment of daily practices can lead to unintentional HIPAA violations, a common issue among healthcare organizations. For example, failing to follow the HIPAA Breach Rule Notification Requirements, whether unintentional or not, can lead to significant consequences.

    In another example, say your healthcare practice has been using online forms to gather new patient information without ensuring they are HIPAA-compliant. While this may have been a small oversight, these forms resulted in the theft of your patientsโ€™ protected health information (PHI).

    This could have been prevented by following HIPAA compliance and cybersecurity best practices, such as proper training and conducting assessments. Utilizing one of these 5 HIPAA-compliant form builders helps to ensure HIPAA compliance requirements.

    Impact of Data Breaches on Healthcare Organizations

    Data breaches can significantly impact healthcare organizations, both financially and reputationally.

    • Legal and financial consequences: Healthcare organizations may face legal and financial consequences as a result of data breaches. This may include fines, penalties, and legal settlements, as well as potential lawsuits from affected patients.
    • Loss or theft of PHI: A data breach can result in the loss or theft of PHI, which can be very costly to remediate. The healthcare organization may be required to offer credit monitoring or identity theft protection services to affected patients, which can be expensive. The organization may also have to pay fines and penalties, both from regulatory bodies and potentially from affected patients who may take legal action.
    • Reputational damage: A data breach can harm the organization’s reputation. Patients may lose trust in the organization’s ability to protect their PHI and seek services elsewhere. This can result in a loss of revenue and difficulty in attracting new patients.
    • Operational disruption: A data breach can disrupt the normal operations of a healthcare organization. Organizations may need to dedicate significant resources to investigating and resolving the breach, including IT resources, staff time, and external consulting services. This can result in operational disruptions, increased costs, and diversion of resources away from other critical activities.

    Why Are Data Breaches Getting Costly?

    There are several reasons behind the rising cost of data breaches:

    Increased Use of Technology

    The increased use of technology has created a larger attack surface for cybercriminals to target. Take Microsoft statistics, for example. In 2020, Microsoft Office 365 usage rose by 20%. However, about 67% of IT leaders who use this software reported an increase in data breaches.

    With the proliferation of connected devices, cloud computing, and the Internet of Things (IoT), the volume of data generated and transmitted has skyrocketed. This provides more opportunities for cybercriminals to infiltrate systems and networks.

    Increased Implementation of Data Protection Regulations

    Another factor contributing to the rising cost of data breaches is the growing regulatory landscape around data protection. Many countries and regions have implemented stringent data protection laws, such as HIPAA, the European Union’s General Data Protection Regulation (GDPR), and the California Consumer Privacy Act (CCPA).

    They impose significant fines and penalties for non-compliance. In the event of a data breach, organizations may face not only the direct costs of investigating and mitigating the breach but also regulatory fines and legal liabilities. These costs can add up quickly, leading to significant financial burdens.

    Increased Online Presence

    The impact of data breaches extends beyond financial costs. Businesses also face reputational damage, loss of customer trust, and potential legal liabilities. In today’s hyper-connected world, news of a data breach can spread quickly through social media and other online channels, resulting in negative publicity and damage to a company’s brand image.

    Customers may lose trust in the affected organization’s ability to protect their data, leading to customer churn and loss of business opportunities. Additionally, businesses may face legal actions from affected customers, partners, or regulators, resulting in costly legal battles and financial settlements.

    Conclusion

    It is clear from the IBM Security Cost of a Data Breach Report 2022 that data breaches are becoming more expensive for organizations, with the financial impact of such incidents rising each year. Healthcare organizations, in particular, are at risk due to the sensitive data stored within their systems.

    Maintaining HIPAA compliance is crucial to protect patients’ privacy and avoid penalties for non-compliance. Colington Consulting can assist in conducting HIPAA security risk assessments, developing risk management plans, and providing workforce security awareness and privacy training to reduce the risk of data breaches and HIPAA violations.

    By taking the necessary steps to protect sensitive data, organizations can prevent the costly consequences of data breaches and safeguard their reputation and finances. Don’t wait for a data breach to occur; contact Colington Consulting today to protect your organization’s sensitive information.

  • 6 More HIPAA Breaches Reported

    With healthcare attention clearly focused on combating the coronavirus, there were six more data breaches that occurred within a few days as the year began. The breaches reported by healthcare organizations, likely resulting in the unauthorized releases of patient data for at least 8,701 patients. As the sheer number of data breaches continues to rise, so too does your responsibility to protect the people who rely on your services. What happened in these latest occurrences, and what steps should you take to fulfil your obligation to prevent it from happening within your own organization?

    Kaiser Permanente is breached once again.

    Kaiser Permanente already had 4 data breaches by the time reports came out back in 2014. Then, in 2018, at least two more were reported. And then again in October of 2019. Now the latest breach occurred when Kaiser Permanente recently discovered letters have accidentally been mailed to patientsโ€™ former addresses. The HHSโ€™ Office for Civil Rights (OCR) breach portal indicates up to 500 patients may have been affected in this one. (This is not counting their prior breaches.)

    Riverview Health also experienced a mailing error.

    Much like Kaiser Permanenteโ€™s latest breach, this one also happened due to a mailing error. This time, however, the mix up exposed the names of 2,610 patients. Fortunately, no financial information – such as credit or debit card numbers – or medical data was exposed. However, the methods of patient notification used by Riverview are currently under review as a result of this incident.

    Harris Health System lost PHI during transport.

    On Friday, February 28th, Harris Health System announced that it was notifying 2,298 patients of a privacy breach that happened on December 30, 2019. Two envelopes that contained 143 pages of protected health information (PHI) were lost in transport to Ben Taub Hospital, which were being sent there for scanning and archiving in Harris Health’s electronic medical record system. The envelopes are thought to contain information on patients seen at Gulfgate Health Center from December 9, 2019 and December 27, 2019.

    Community Mental Health Council mental health records were found dumped in an alley.

    In 2012, the Community Mental Health Council was forced to permanently close its clinics due to lack of funding. Long after the fact, however, hundreds of medical records from CMHCl have been found abandoned in an alley in West Englewood, Chicago. The documents included full names, addresses, Social Security numbers, diagnosis information, medical records, and more. City officials are currently trying to determine who was responsible for dumping the records.

    Armada Physical Therapy had a server carried off.

    Data breaches through hacking, phishing scams, and mailing errors are nothing new. But what makes the breach of Armada Physical Therapy stand out is that this time around, someone actually broke into the building and stole an entire server. At the time of writing, the investigation is still ongoing, and the stolen server has not yet been recovered. The server holds intake forms that contain names, addresses, telephone numbers, email addresses, insurance numbers, and Social Security numbers for around 500 patients.

    Elk Ridge Dentistry had a hard drive stolen.

    Unlike the incident with Armada, one would imagine that stealing a portable hard drive is at least a bit easier than making off with an entire server. At least one such hard drive was stolen from Elk Ridge Dentistry. The hard drive in question was used to store backups, and was actually among several items taken from the practice. Much like Armadaโ€™s server, the hard drive has not yet been recovered. To make matters worse, it contained the records of 2,793 patients, which included names, addresses, dates of birth, healthcare information, X-ray images, Social Security numbers, treatment consent forms, referral letters, and emails.

    Take Action Now

    So many different occurrences all happening within such a short time should give anyone cause for serious alarm. The numbers are against you, and we here at Colington Consulting donโ€™t want you to become yet another statistic. Even as COVID-19 events have impacted healthcare organizations, we are still able to provide the majority of our services remotely. We are available and can set up an initial consultation to talk about our services and how we can assist your organization. Call us today at 844.740.7100 and find out how we can help you protect your patients from incidents like these.

  • Substantial HIPAA Data Breaches: Only a Matter of Time

    by Jay Hodes, President – Colington Consulting

    With all the news about data breaches and the potential for personally identifiable information (PII) to make its way into the wrong hands of criminals or hackers, is it only a matter of time before there is a substantial breach of patient records? When checking the U.S. Department of Health and Human Services (HHS) Breach List, you will find these occurrences already happening on a regular basis. In June, the state of Montana announced 1.3 million people were affected by a recent health records data breach.

    Between March 1 and May 30, 2014, there were eight separate breach notifications made to HHS, each affecting 500 or more individuals, totaling almost 35,000 compromised patient records. The largest breach affected more than 8,800 individuals from an HMO and related insurance provider. But these breaches affect small healthcare providers, also. One of the reported breaches affecting 1,000 individuals was at a podiatry office and another at a dental practice that involved 6,900 individuals. There is no percipience with the size and type of healthcare practice, and most breaches appear to be theft related.

    There is usually limited press coverage of these breaches, except by those who track these industry occurrences. But when a newsworthy and extensive breach of millions of records does happen, it will be front page news. When will the tsunami of a health record breach occur? Regrettably, it may be sooner than later. When the FBI recently warned healthcare providers that their cybersecurity networks are more susceptible than retail and financial sectors, hopefully the alarm bells went off and proper information technology countermeasures are now being implemented.

    According to Chris Albright, network security expert and owner of CMIT Solutions of Centreville (VA), โ€œHackers, just like other predators, always go after the most vulnerable or โ€˜softโ€™ targets first. This approach guarantees the hacker greater success with the least amount of effort. More often than not, data breaches are not professional hackers in the traditional sense. Rather, it is members of the medical staff who know there are no policies or effective security measures in place, and they know the violation will go unnoticed. Healthcare offices that fail to address HIPAA head on are essentially sitting on a time bomb.โ€

    Conducting a HIPAA Risk Assessment is an excellent way to identify vulnerabilities and threats to patient electronic health records. Besides being a fundamental requirement of HIPAA compliance, the assessment helps professionals to recognize problem areas where the potential for unauthorized access, lack of proper internal protocols for tampering and outright theft of protected health information may occur.

    Need Help with Your HIPAA Compliance Program?

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

    Updated on June 21, 2025 and Reviewed By: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert

    Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.

  • PHI – Striking Fear When It Comes to Being Compromised

    by Jay Hodes, Presidentย – Colington Consultingย 

    I am not sure if those tasked with securing protected health information lose sleep every night worrying if they did enough to safeguard the data their organizations maintain. If they are losing sleep, though, that may be a good thing, because it could show how seriously they take this responsibility. But for the rest, that obnoxious wake up alarm that we all hate at times should be the recent ransomware case that occurred at the Hollywood (CA) Presbyterian Medical Center.

    A letter released by Allen Stefanek, President and CEO of the Center, acknowledged that $17,000 in a ransom was paid to the alleged perpetrators to get their electronic health records back. Stefanek stated the โ€œquickest and most efficient way to restore our systems and administrative functions was to pay the ransom and obtain the decryption key.โ€

    If a hospital system can be put into a virtual shutdown, how vulnerable are millions of small to mid-size providers?

    When conducting HIPAA risk assessments, I ask required questions about contingency, emergency and disaster recovery plans. Some organizations do not realize these are critical elements for HIPAA compliance. Policies and procedures must be in place and address these potential vulnerabilities that could result in a high risk rating. Unless these providers are outsourcing IT services and secure backup is part of the arrangement, many fall short in making sure all PHI maintained is available at all times, regardless of emergency or disaster โ€“ or data being taken hostage, as was the case with Hollywood Presbyterian.

    One of the lessons I learned from my time in Federal law enforcement is to โ€œwhat ifโ€ scenarios to death. Try to determine all the negatives an operation or mission could face, and then have a contingency plan to address each particular scenario. Being prepared is crucial because if something does go bad, a plan is already in place to address it. When it comes to protecting healthcare data, the same philosophy should hold true. There are required HIPAA implementation specifications for the standard of developing and maintaining contingency plans. Policy and procedure must be in place to address areas like data backup, disaster recovery, system criticality analysis and emergency mode operations.

    Although not technically a HIPAA requirement, I always bring up continuity of business operations when talking with clients. It goes beyond needing access to protected health information in emergency conditions. I recommend timelines in cases where a facility cannot be occupied after a natural or man-made disaster and there is the need to assign roles and responsibilities to do certain things, such as locating temporary office space, procuring IT, telecom, and medical equipment and establishing a process to notify patients about the closure or relocation.

    Many larger organizations have procedures in place and routinely test and drill their contingency plans. Small to mid-size organizations must have the same protocols in place; albeit to a lesser extent because of the nature of their business operations.

    Fearing if your organization is going to be compromised is a reality that needs to be faced. Most experts agree it is not if, but when. Having addressed these issues before a breach occurs and having a game plan in place can go a long way in making sure any impact can be minimized as much as possible.

    • Reviewed on June 23, 2026 by: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert
    • Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.
  • OCR Announces Initiative to More Widely Investigate Breaches

    OCR Announces Initiative to More Widely Investigate Breaches Affecting Fewer than 500 Individuals

    by Jay Hodes, President – Colington Consulting

    Since the passage of the Health Information Technology for Economic and Clinical Health Act of 2009 and the subsequent implementation of the Health Insurance Portability and Accountability Act (HIPAA) Breach Notification Rule, OCR has prioritized investigation of reported breaches of protected health information (PHI). The root causes of breaches may indicate entity-wide and industry-wide noncompliance with HIPAAโ€™s regulations, and investigation of breaches provides OCR with an opportunity to evaluate an entityโ€™s compliance programs, obtain correction of any deficiencies, and better understand compliance issues in HIPAA-regulated entities more broadly. ย OCRโ€™s Regional Offices investigate all reported breaches involving the PHI of 500 or more individuals. ย Regional Offices also investigate reports of smaller breaches (involving the PHI of fewer 500 individuals), as resources permit. ย 

    Beginning this month, OCR, through the continuing hard work of its Regional Offices, has begun an initiative to more widely investigate the root causes of breaches affecting fewer than 500 individuals. ย Regional Offices will still retain discretion to prioritize which smaller breaches to investigate, but each office will increase its efforts to identify and obtain corrective action to address entity and systemic noncompliance related to these breaches. ย Among the factors Regional Offices will consider include: ย 

    โ€ข The size of the breach;
    โ€ข Theft ย of or improper disposal of unencrypted PHI;
    โ€ข ย Breaches that involve unwanted intrusions to IT systems (for example, by hacking); The amount, nature and sensitivity of the PHI involved; ย orย 
    โ€ข ย Instances where numerous breach reports from a particular covered entity or business associate raise similar issues. ย ย 

    Regions may also consider the lack of breach reports affecting fewer than 500 individuals when comparing a specific covered entity or business associate to like-situated covered entities and business associates. ย 

    Take Action Now

    If HIPAA compliance assistance is needed for your organization, we specialize in putting compliance programs in place or assessing your current program. We provide a full range of services that include conducting the required HIPAA Risk Assessment, writing and customizing a HIPAA Risk Management Plan (HIPAA Policies and Procedures) for your organization, and providing your entire staff annual required HIPAA Security Awareness & Privacy Training through our web-based platform. Our fees are based on what specifically your organization will need to meet regulatory requirements and reasonably priced to accommodate any budget.

    Letโ€™s start the process with a free, initial consultation. In as little as 15 minutes, we can evaluate your current compliance program to determine if all mandatory privacy and security safeguards are in place to meet government regulations.

    This blog was previously posted August 19, 2016

  • The Danger of Disregarding Risk Analysis: The Anthem Case

    by Jay Hodes, President – Colington Consulting

    Anthem, Inc., a defined Business Associate that provided administrative support services for the Anthem Affiliated Covered Entities (Anthem ACE), has committed to a $16 million settlement to the U.S. Department of Health and Human Services, Office for Civil Rights (OCR). This is the largest settlement ever announced by OCR.ย  The outcome of this investigation determined a high risk of HIPAA Security Rule and HIPAA Privacy Rule violations due to a series of โ€œundetected continuous and targeted cyber attack[s] for the apparent purpose of extracting data, otherwise known as an advanced persistent threat attackโ€ that exposed the ePHI of approximately 79 million users between December 2, 2014 and January 27, 2015, including names, social security numbers, medical identification numbers, addresses, dates of birth, email addresses, and employment information.

    The risk was found to have originated via a malicious email phishing attack that at least one Anthem, Inc. employee responded to, thus allowing the cyber attackers easy access.

    The following are the potential violations uncovered by the HHS investigation:

    • The requirement to conduct an accurate and thorough risk analysis of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of all ePHI held by Anthem
    • The requirement to implement sufficient procedures to regularly review records of information system activity
    • The requirement to identify and respond to detection of the security incident leading to this breach
    • The requirement to implement sufficient technical policies and procedures for electronic information systems that maintain electronic protected health information to allow access only to those persons or software programs that have been granted access rights
    • The requirement to prevent unauthorized access to the ePHI of 78,800,000 individuals whose information was maintained in Anthem’s enterprise data warehouse

    The Corrective Action Plan (CAP) signed onto by Anthem includes the following terms:ย 

    • Conducting a detailed and thorough Risk Analysis within 90 days of the CAPโ€™s effective date, including a Statement of Work (SOW) submitted to HHS detailing the process of this Risk Analysis. After receiving appropriate or necessary feedback and input from HHS, then Anthem has 150 days to implement new or updated security measures based on the Risk Analysis findings as well as consequent responses made to the Analysis by HHS.
    • Conducting a thorough review of policies and procedures to ensure thorough compliance with the HIPAA Security Rule.
    • Distributing all updated policies and procedures throughout Anthemโ€™s network of employees and contractors, and ensuring proper transfer of training for this same content.

    As a CE or BA, not enough can be said about the dangers of storing ePHI without proper risk management and analysis.ย In my opinion, Anthem, Inc.โ€™s payment and CAP is considered disproportionate to the potential violations carried out due to this breach and the number of individuals affected.

    Consistent, periodic review of your organizationโ€™s security measures and risk management plan is key to ensuring ongoing compliance with the HIPAA Privacy Rule and HIPAA Security Rule.ย  Despite the size of your organization, effective overall HIPAA compliance program is vital and can help to prevent breaches from occurring.ย 

    This blog was previously posted November 13, 2018

  • Is a HIPAA Violation a Reportable Breach?

    Just because a member of an organizationโ€™s workforce violates HIPAA policies and procedures, it is not necessarily a breach reporting requirement. The significant determination is the extent to which any protected health information (PHI) may have been compromised based on breach rule guidance. So, before getting too technical regarding that determination, here are some cases to consider:

    1. An employee for a healthcare software company loses a computer containing the PHI of 2000 patients. Reportable breach?
    2. A hospital system is the victim of a ransomware attack. Reportable breach?

    A breach is generally an impermissible use or disclosure under the Privacy Rule that compromises the

    security or privacy of the PHI. An impermissible use or disclosure of PHI is presumed to be a breach unless the covered entity or business associate, as applicable, demonstrates that there is a low probability that the PHI has been compromised based on a risk assessment of at least the following factors:

    • The nature and extent of the PHI involved, including the types of identifiers and the likelihood of re-identification;
    • The unauthorized person who used the PHI or to whom the disclosure was made;
    • Whether the PHI was actually acquired or viewed; and
    • The extent to which the risk to the PHI has been mitigated.

    Going through this type of breach โ€œrisk assessmentโ€ can be challenging, especially in trying to determine if any PHI was acquired or viewed. To further complicate this process, the guidance does not specify what exactly a โ€œlow probabilityโ€ is. So, this assessment process will take some work.

    Begin by using a decision tree and asking questions such as โ€œWas the PHI disclosure to a person who reasonably would have not been able to retain that information?โ€ and โ€œWas the PHI secured by encryption?โ€ The resulting series of yes or no responses will help to determine whether a breach notification is required.

    In most of these cases, the organizationโ€™s HIPAA Privacy and Security Officials should take the lead with this process. There may be a need to involve the organizationโ€™s healthcare and privacy attorney for advice. Experience and expertise with the process are clearly essential to helping determine probability.

    It is important to document the results, especially in those cases in which a determination was made that it was not a reportable breach. If, for some reason, any of the PHI was in fact compromised and a breach report was not made, demonstrating due diligence in the event an HHS Office for Civil Rights (OCR) investigation is necessary.

    Referencing the numbered case examples above:

    1. This would be a reportable breach if the PHI was not encrypted. However, if the PHI was encrypted, it could be an organizational HIPAA violation based on policies and procedures for mobile devices.
    2. This example is going to be a fact-specific determination. In 2016, OCR issued guidelines on the topic of ransomware attacks. If the PHI was encrypted, it may not be reportable. But any unsecured PHI will be a reportable breach. (See the full fact sheet.) In this case, the possibility exists that there may also be a HIPAA violation based on the cause of the attack and whether proper safeguards were followed by a workforce member or members.

    My advice is to make sure your organizationโ€™s HIPAA Sanction policies and procedures are clear for any violations, even for those cases that are not reportable. Ensure the organization has a comprehensive breach notification policy and accompanying procedures. Be familiar with the breach risk assessment process and be prepared should an impermissible use or disclosure occur.

    This blog was previously posted January 7, 2019

  • Office for Civil Rights (OCR) – Two Significant Announcements

    The U.S. Department of Health and Human Services, Office for Civil Rights (OCR) had two significant announcements this past week resulting in total of $4.6 million for a settlement and imposed penalty.ย  The two cases, one involving a public agency, the Texas Health and Human Services Commission (TX HHSC) and the second, a university medical center, the University of Rochester Medical Center (URMC).

    Both cases demonstrate OCR is continuing on an aggressive path to address reported breaches and investigate how organizations are just not being proactive with HIPAA compliance requirements.These investigations uncovered a slew of problems, especially in the Texas case.ย  What was troubling about this case, is the TX HHSC had such poor audit controls, it could not determine the number of persons who inappropriately accessed the protected health information in question.

    In the URMC case, it determined โ€œidentification of a lack of encryption as a high risk to ePHI, URMC [still] permitted the continued use of unencrypted mobile devices.โ€ย  This is a clear case of somebody dropping the ball due to reasons one can only speculate about.ย 

    If OCRโ€™s track record is similar to recent years, expect more settlement announcements to be made before the end of the year.ย  With the holidays quickly approaching, OCR may not be spreading good cheer for some.

    Read the TX HHSC Press Release

    Read the URMC Press Release