Texas Health and Human Services Commission Fined $1.6M for HIPAA Breach

Nov. 11, 2019

The Texas Health and Human Services Commission (TX HHSC) has been hit with a $1.6 million civil money penalty by the Office for Civil Rights (OCR) for allowing some patient data to be viewable over the Internet.

TX HHSC is part of the Texas HHS system, and has a wide range of responsibilities, including operating state supported living centers, providing mental health and substance use services, regulating child care and nursing facilities; and administering hundreds of programs for people who need assistance, including supplemental nutrition benefits and Medicaid.

The Department of Aging and Disability Services (DADS), a state agency that administered long-term care services for people who are aging, and for people with intellectual and physical disabilities, was reorganized into TX HHSC in September 2017.

According to a recent OCR press release, DADS filed a breach report with the department stating that the electronic protected health information (ePHI) of 6,617 individuals was viewable over the internet, including names, addresses, social security numbers, and treatment information.

The breach occurred when an internal application was moved from a private, secure server to a public server and a flaw in the software code allowed access to ePHI without access credentials, according to officials.

OCR's investigation determined that, in addition to the impermissible disclosure, “DADS failed to conduct an enterprise-wide risk analysis, and implement access and audit controls on its information systems and applications as required by the HIPAA Security Rule. Because of inadequate audit controls, DADS was unable to determine how many unauthorized persons accessed individuals' ePHI.”

OCR Director Roger Severino said in a statement, “Covered entities need to know who can access protected health information in their custody at all times. No one should have to worry about their private health information being discoverable through a Google search."

Sponsored Recommendations

Care Access Made Easy: A Guide to Digital Self-Service for MEDITECH Hospitals

Today’s consumers expect access to digital self-service capabilities at multiple points during their journey to accessing care. While oftentimes organizations view digital transformatio...

Going Beyond the Smart Room: Empowering Nursing & Clinical Staff with Ambient Technology, Observation, and Documentation

Discover how ambient AI technology is revolutionizing nursing workflows and empowering clinical staff at scale. Learn about how Orlando Health implemented innovative strategies...

Enabling efficiencies in patient care and healthcare operations

Labor shortages. Burnout. Gaps in access to care. The healthcare industry has rising patient, caregiver and stakeholder expectations around customer experiences, increasing the...

Findings on the Healthcare Industry’s Lag to Adopt Technologies to Improve Data Management and Patient Care

Join us for this April 30th webinar to learn about 2024's State of the Market Report: New Challenges in Health Data Management.