Device Manufacturer Will Pay $2.5M to Settle Potential HIPAA Noncompliance

April 24, 2017
CardioNet, a Malvern, Pa.-based device manufacturer and a subsidiary of BioTelemtry, has agree to pay a $2.5 million settlement with the U.S. Department of Health and Human Services, Office for Civil Rights (OCR) due to potential noncompliance with the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy and Security Rules.

CardioNet, a Malvern, Pa.-based device manufacturer and a subsidiary of BioTelemtry, has agree to pay a $2.5 million settlement with the U.S. Department of Health and Human Services, Office for Civil Rights (OCR) due to potential noncompliance with the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy and Security Rules.

According to a press release from HHS, the potential HIPAA compliance stems from the impermissible disclosure of unsecured electronic protected health information (ePHI) following the theft of an employee’s laptop. As part of the resolution agreement, CardioNet also agreed to implement a corrective action plan. The settlement is the first involving a wireless health services provider, according to HHS, as CardioNet provides remote mobile monitoring of and rapid response to patients at risk for cardiac arrhythmias.

HHS report states that in January 2012, CardioNet reported to the HHS’ OCR that a workforce member’s laptop was stolen from a parked vehicle outside of the employee’s home. The laptop contained the ePHI of 1,391 individuals. OCR’s investigation into the impermissible disclosure revealed that CardioNet had “an insufficient risk analysis and risk management processes in place at the time of the theft,” HHS stated. Additionally, “CardioNet’s policies and procedures implementing the standards of the HIPAA Security Rule were in draft form and had not been implemented.” Further, the company was unable to produce any final policies or procedures regarding the implementation of safeguards for ePHI, including those for mobile devices, according to HHS.

Sponsored Recommendations

A Cyber Shield for Healthcare: Exploring HHS's $1.3 Billion Security Initiative

Unlock the Future of Healthcare Cybersecurity with Erik Decker, Co-Chair of the HHS 405(d) workgroup! Don't miss this opportunity to gain invaluable knowledge from a seasoned ...

Enhancing Remote Radiology: How Zero Trust Access Revolutionizes Healthcare Connectivity

This content details how a cloud-enabled zero trust architecture ensures high performance, compliance, and scalability, overcoming the limitations of traditional VPN solutions...

Spotlight on Artificial Intelligence

Unlock the potential of AI in our latest series. Discover how AI is revolutionizing clinical decision support, improving workflow efficiency, and transforming medical documentation...

Beyond the VPN: Zero Trust Access for a Healthcare Hybrid Work Environment

This whitepaper explores how a cloud-enabled zero trust architecture ensures secure, least privileged access to applications, meeting regulatory requirements and enhancing user...