Category: HIPAA Violation

  • OCR Announces a Significant HIPAA Settlement of $1.3 Million

    OCR just announced a significant HIPAA settlement of $1.3 million with LA Care, one of the largest health plan providers in the country. There where substantial “potential” violations found by OCR which included failure an organization-wide risk assessment and failure to implement sufficient procedures to regularly review records of information system activity.

    LA Care agreed to a comprehensive corrective action plan for three years to ensure compliance with HIPAA requirements.

    Read the full press release: https://www.hhs.gov/about/news/2023/09/11/hhs-office-civil-rights-settles-with-la-care-health-plan-potential-hipaa-security-rule-violations.html

  • Is a HIPAA Violation a Reportable Breach?

    Just because a member of an organizationโ€™s workforce violates HIPAA policies and procedures, it is not necessarily a breach reporting requirement. The significant determination is the extent to which any protected health information (PHI) may have been compromised based on breach rule guidance. So, before getting too technical regarding that determination, here are some cases to consider:

    1. An employee for a healthcare software company loses a computer containing the PHI of 2000 patients. Reportable breach?
    2. A hospital system is the victim of a ransomware attack. Reportable breach?

    A breach is generally an impermissible use or disclosure under the Privacy Rule that compromises the

    security or privacy of the PHI. An impermissible use or disclosure of PHI is presumed to be a breach unless the covered entity or business associate, as applicable, demonstrates that there is a low probability that the PHI has been compromised based on a risk assessment of at least the following factors:

    • The nature and extent of the PHI involved, including the types of identifiers and the likelihood of re-identification;
    • The unauthorized person who used the PHI or to whom the disclosure was made;
    • Whether the PHI was actually acquired or viewed; and
    • The extent to which the risk to the PHI has been mitigated.

    Going through this type of breach โ€œrisk assessmentโ€ can be challenging, especially in trying to determine if any PHI was acquired or viewed. To further complicate this process, the guidance does not specify what exactly a โ€œlow probabilityโ€ is. So, this assessment process will take some work.

    Begin by using a decision tree and asking questions such as โ€œWas the PHI disclosure to a person who reasonably would have not been able to retain that information?โ€ and โ€œWas the PHI secured by encryption?โ€ The resulting series of yes or no responses will help to determine whether a breach notification is required.

    In most of these cases, the organizationโ€™s HIPAA Privacy and Security Officials should take the lead with this process. There may be a need to involve the organizationโ€™s healthcare and privacy attorney for advice. Experience and expertise with the process are clearly essential to helping determine probability.

    It is important to document the results, especially in those cases in which a determination was made that it was not a reportable breach. If, for some reason, any of the PHI was in fact compromised and a breach report was not made, demonstrating due diligence in the event an HHS Office for Civil Rights (OCR) investigation is necessary.

    Referencing the numbered case examples above:

    1. This would be a reportable breach if the PHI was not encrypted. However, if the PHI was encrypted, it could be an organizational HIPAA violation based on policies and procedures for mobile devices.
    2. This example is going to be a fact-specific determination. In 2016, OCR issued guidelines on the topic of ransomware attacks. If the PHI was encrypted, it may not be reportable. But any unsecured PHI will be a reportable breach. (See the full fact sheet.) In this case, the possibility exists that there may also be a HIPAA violation based on the cause of the attack and whether proper safeguards were followed by a workforce member or members.

    My advice is to make sure your organizationโ€™s HIPAA Sanction policies and procedures are clear for any violations, even for those cases that are not reportable. Ensure the organization has a comprehensive breach notification policy and accompanying procedures. Be familiar with the breach risk assessment process and be prepared should an impermissible use or disclosure occur.

    This blog was previously posted January 7, 2019

  • Not Worried About Your Patients? Worry About Your Bottom Line?

    Weโ€™re always talking about how not complying with HIPAA regulations badly affects patients. Their data is exposed to malicious entities. Their trust in your organization wanes. Even if youโ€™re not worried about the moral implications or your public perception, the fact is youโ€™re not off the hook for noncompliance. There are severe penalties for not following the rules. And thatโ€™s what weโ€™ll be discussing in todayโ€™s article.

    A Breakdown of HIPAA Fines

    Penalties for HIPAA noncompliance are broken down into four categories of fines:

    1. Willful neglect with no corrective action taken.
    2. Willful neglect with corrective action taken.
    3. Reasonable cause for noncompliance.
    4. No knowledge of noncompliance.

    Each level of noncompliance comes with its own financial penalty for your company or organization. Letโ€™s take a closer look at what each one means, and what its penalty is.

    Willful Neglect with No Corrective Action

    This is by far the most severe form of noncompliance, and therefore comes tagged with the harshest of government fines. From a legal standpoint, willful neglect is defined as a “conscious, intentional failure or reckless indifference.โ€ If you work in the healthcare industry, thereโ€™s a good chance youโ€™ve at least heard of HIPAA. Weโ€™ve reached a point where it is very difficult for organizations to claim ignorance of it. If it looks as though you havenโ€™t even bothered to make the necessary changes, thereโ€™s a good chance you could be hit with this very serious charge. It comes with a nasty $50,000 minimum penalty for each violation, and can cost your organization up to a whopping $1,500,000 annually.

    Willful Neglect with Corrective Action

    If a company or organization is found guilty of willful neglect as defined above, resolving the noncompliance issue in a timely fashion will reduce the associated penalty. Itโ€™s still a hefty price thatโ€™s nothing to sneeze at however, and your best option of course is to comply with the regulations in the first place. After making the necessary changes, you could instead be hit with a $10,000 penalty for each violation, up to a maximum of $250,000 annually. The difference isnโ€™t negligible at least, and is greatly preferable to ignoring the problem – both for your patients and for your companyโ€™s bottom line.

    Reasonable Cause

    The legal definition for reasonable cause in regard to HIPAA compliance is as follows:

    โ€œAn act or omission in which a covered entity or business associate knew, or by exercising reasonable diligence would have known, that the act or omission violated an administrative simplification provision, but in which the covered entity or business associate did not act with willful neglect.โ€ While not as serious as โ€œwillful neglect,โ€ it still comes with a heavy price tag of $1,000 for each violation and up to $100,000 annually.

    No Knowledge

    Noncompliance is to be considered โ€œwithout knowledgeโ€ if the covered entity or individual did not know (and by exercising reasonable diligence would not have known) the action in question was a HIPAA violation. This is incredibly common, and is a huge culprit for many violations. This is why it is especially important to train your employees and make absolutely certain everyone knows and follows the regulations. Not rigorously training – and refreshing – your employees in HIPAA compliance can cost you $100 for every single violation, and up to $25,000 a year in damages. Teaching your staff the right way of doing things, taking the right precautions and putting processes in place will help you best to avoid these fines.

    Remember, there can be hefty fines for not following regulations. But most importantly, itโ€™s important to protect the people youโ€™re serving. Their lives are in your hands. Let us help you help them – and yourselves.ย  Give us a call today at 800-733-6379 for a free, no obligation, initial consultation.ย