New York Hospitals Pay Largest HIPAA Settlement to Date

May 8, 2014
Two New York-based hospitals that participate in a joint agreement are agreeing to pay nearly $5 million for a data breach in what is the largest settlement of a violation of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy and Security Rules to date.

Two New York-based hospitals that participate in a joint agreement are agreeing to pay nearly $5 million for a data breach in what is the largest settlement of a violation of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy and Security Rules to date.

The New York and Presbyterian Hospital (NYP) and Columbia University (CU), which participate in a joint arrangement in which CU faculty members serve as attending physicians at NYP, paid out $4.8 million to the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) for failing to secure thousands of patients’ electronic protected health information (ePHI) held on their network. The breach occurred when a physician employed by CU who developed applications for both NYP and CU attempted to deactivate a personally-owned computer server on the network containing NYP patient ePHI. The deactivation of the server resulted in ePHI being accessible on internet search engines, due to a lack of safeguards. The hospitals only learned of the breach when a patient complained they had found the ePHI of their deceased partner on the internet.

According to OCR, both healthcare provider organizations failed to ensure that the server was secure nor had they done a risk analysis. Further, OCR says, failed to implement appropriate policies and procedures for authorizing access to its databases and failed to comply with its own policies on information access management.

“When entities participate in joint compliance arrangements, they share the burden of addressing the risks to protected health information,” stated Christina Heide, Acting Deputy Director of Health Information Privacy for OCR. “Our cases against NYP and CU should remind health care organizations of the need to make data security central to how they manage their information systems.”

Recently, researchers revealed that since the Health Information Technology for Economic and Clinical Health (HITECH) Act forced providers to notify HHS when they had a breach affecting 500 or more patients, there have been 804 large breaches of PHI. The report, Redspin, Inc., a Carpinteria, Calif.-based provider of IT security assessments, revealed that nearly 30 million Americans have had their health information breached or inadvertently disclosed since 2009.

Read the source article at hhs.gov

Sponsored Recommendations

State of the Market: Transforming Healthcare; Strategies for Building a Resilient and Adaptive Workforce

The U.S. healthcare system is facing critical challenges, including workforce shortages, high turnover, and regulatory pressures. This guide highlights the vital role of technology...

How AI-Native Locating Intelligence Revolutionizes the RTLS market

Discover how leveraging an RTLS solution with artificial intelligence as the location engine can increase efficiency, improve safety, and elevate care without the compromises ...

Harnessing the True Power of Cultural, Clinical and Operational Data

Optimize healthcare performance by combining clinical, operational, and cultural insights. A deeper understanding of team factors improves care and resource management.

How Digital Co-Pilots for patients help navigate care journeys to lower costs, increase profits, and improve patient outcomes

Discover how digital care journey platforms act as 'co-pilots' for patients, improving outcomes and reducing costs, while boosting profitability and patient satisfaction in this...