Category: HIPAA Penalties

  • How to Avoid a $100,000 HIPAA Settlement

    By Jay Hodes, President โ€“ Colington Consulting

    Question: How can an organization avoid a large HIPAA settlement with the HHS Office for Civil Rights (OCR)?

    Up to this point, the OCR has settled HIPAA violation cases with predominantly larger healthcare organizations. However, OCRโ€™s enforcement priority and direction has changed and all healthcare providers, regardless of size, must be on guard for the โ€œmessage sending casesโ€ on which OCR is currently focusing.

    As a case in point, on the first day of the recent National HIPAA Summit held in Arlington, Virginia, OCR announced a $100,000 settlement for a HIPAA violation case involving the practice of Steven A. Porter, M.D., a gastroenterological services provider and solo practitioner. This โ€œmessage sendingโ€ was twofold: 1) Serena Mosley-Day, Senior Advisor for HIPAA Compliance and Enforcement for OCR, provided a presentation emphasizing that small providers are not immune to OCR scrutiny and must meet the same requirements under HIPAA as do larger healthcare organizations; and 2) Announcing the settlement at a Summit where attendees included attorneys, Chief Compliance Officers, HIPAA Security and Privacy Officials, IT and cybersecurity experts was timed for maximum impact.

    According to the HIPAA Settlementโ€™s press release, Dr. Porter โ€œfiled a breach report with OCR related to a dispute with a business associate. OCRโ€™s investigation determined that Dr. Porter had never conducted a risk analysis at the time of the breach report, and despite significant technical assistance throughout the investigation, had failed to complete an accurate and thorough risk analysis after the breach and failed to implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level.โ€

    OCR Director Roger Severinoโ€™s comments in the press release are especially noteworthy. He states that โ€œAll health care providers, large and small, need to take their HIPAA obligations seriously,โ€ and โ€œthe failure to implement basic HIPAA requirements, such as an accurate and thorough risk analysis and risk management plan, continues to be an unacceptable and disturbing trend within the health care industry.โ€

    OCR has previously said that 95% of reported breaches are resolved with technical guidance. The key to avoiding a costlier outcome is to demonstrate to OCR that your organization has a HIPAA compliance plan in place and to cooperate with the OCR breach investigation.

    Answer: To reduce the risk of penalty or settlement or the cost of mitigating a breach, an organization MUST implement and maintain a HIPAA compliance program as follows:

    • Develop and implement policies and procedures to address all the HIPAA Security Standards and Implementation Specifications.
    • Prepare a HIPAA Risk Management Plan that includes policies and procedures, asset inventories, HIPAA-related forms and reports, a facility security plan, and a documented contingency plan.
    • Conduct he required HIPAA Security Risk Assessment.
    • Provide HIPAA Security Awareness Training to the entire workforce.
    • Assign HIPAA Security and Privacy Officer(s) to manage a HIPAA compliance program. Regardless of size, an organization must designate a workforce member(s) to handle these required responsibilities.

    Take Action Now

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

  • What Comes Up, Must Go Down: Regulatory Trends and HIPAA

    Enforcement of HIPAA mandates by the HHS Office for Civil Rights (OCR) are more aggressive than ever before, โ€œtotaling $28.7 million from enforcement actionsโ€ in 2018, an increase of 22% from the last record total of $23.5 million in 2016. ย According to an OCR press release, 2018 saw that office establish โ€œan all-time record yearโ€ in HIPAA enforcement activity, settling โ€œ10 casesโ€ and being โ€œgranted summary judgment in a case before an Administrative Law Judge.โ€ One of these 10 cases was the watershed HIPAA settlement with Anthem, Inc. for $16 million.

    OCR Settlements* and Judgement** for 2018

    Jan – FileFax*ย  –ย  $100,000

    Jan – Fresenius Medical Care* – $3,500,000

    Jun – MD Anderson** – $4,348,000

    Augย  – Boston Medical Center*ย  –ย  $100,000

    Sep – Brigham & Womenโ€™s Hospital* – $384,000

    Sep – Mass. General Hospital* – $515,000

    Sep – Advanced Care Hospitalists* – $500,000

    Oct – Allergy Associates of Hartford* – $125,000

    Oct – Anthem, Inc* – $16,000,000

    Nov – Pagosa Springs* – $111,400

    Dec – Cottage Health* – $3,000,000

    Total โ€“ Settlements & Judgement:ย  $28,683,400

    While the current administration did and continues to tout a posture of deregulation, the reality on the ground for organizations that must comply with HIPAA is that OCR has only strengthened its enforcement mechanisms, showing very little tolerance for security and privacy breaches arising from:

    • The mismanagement, or lack of proper storage, transmission, or disposal of patient PHI and ePHI.
    • An incomplete or missing Business Associate Agreement (BAA) made with any and all vendors who might be considered a Business Associates (BA) under HIPAA.
    • Cyberattacks via successful email phishing attempts targeting not just Covered Entity (CE) workers or employees, but also workers or employees of any vendor affiliated with theย  CE.
    • Incompatible or insufficient risk analysis and risk management processes on the part of the CE.

    Out of these 11 instances of verified HIPAA violations,

    • 6 CEs were found to have mismanaged or improperly stored, transmitted, or disposed of patient PHI and ePHI (Fresenius Medical Care North America, FileFax, Inc., MD Anderson, Allergy Associates of Hartford, Pagosa Springs, and Cottage Health)
    • 3 CEs did not have a BAA in place to manage vendors who are considered to be BAs under HIPAA (Advanced Care Hospitalists, Pagosa Springs, and Cottage Health)ย ย 
    • 1 CE experienced an email phishing cyber-attack (Anthem, Inc.)ย 
    • 4 CEs made PHI or patient privacy vulnerable by exposing the same via TV shows, interviews, or recordings (Allergy Associates of Hartford, Boston Medical Center, Brigham and Womenโ€™s Hospital, and Massachusetts General Hospital)
    • 4 CEs lacked HIPAA-mandated risk assessment, risk analysis, risk notification, or risk management protocols (Cottage Health, MD Anderson, Advanced Care Hospitalists, and Fresenius Medical Care North America)

    From this analysis, it can be ascertained that CEs and BAs can avoid facing settlements and judgements due to violations of the HIPAA Privacy Rule and the HIPAA Security Rule by instituting the following โ€œgolden rulesโ€ and ensuring their staff are fully trained in the same:

    • Do have robust and comprehensive plan to assess, identify, report, respond, and manage all security or privacy risks.
    • Do ensure a signed and completed BAA is on file for all BAs
    • Do have highly specific protocols in place governing the collection, storage, transmission, and disposal of patient PHI and ePHI.

    Best practices include annual and periodic training for their workforce, conducting the required security risk assessment in an ongoing/periodic manner, and internally enforcing HIPAA policies and procedures to cover the organizationโ€™s security management processes.

    Organizations, large and small, must be aware of the aggressive posture of enforcement and record settlement amounts under OCR and this current administration. My advice for any organization is to conduct a thorough evaluation of the current HIPAA compliance in place. Make sure all the requirements are covered.ย  If a compliance program is not is place, consider outsourcing and let a consultant do the heavy lifting.ย Often times, a consultant can get the program in place much quicker than relying on the organizationโ€™s internal staff.

    This blog was previously posted February 12, 2019