OCR Fines Cancer Care Group $750K for Potential HIPAA Security Violations

Sept. 3, 2015
An Indiana-based radiation oncology practice, Cancer Care Group, P.C., agreed to pay $750,000 in potential violations of the Health Insurance Portability and Accountability Act (HIPAA) Privacy and Security Rules stemming from a 2012 data breach.

An Indiana-based radiation oncology practice, Cancer Care Group, P.C., agreed to pay $750,000 in potential violations of the Health Insurance Portability and Accountability Act (HIPAA) Privacy and Security Rules stemming from a 2012 data breach.

The settlement was agreed upon with the U.S. Department of Health and Human Services’ Office for Civil Rights (OCR). In addition to the fines, the practice will adopt a corrective action plan to correct deficiencies in its HIPAA compliance program, according to OCR.

The potential violations stem from an incident in July 2012 regarding a breach of unsecured electronic protected health information (ePHI). Cancer Care notified OCR that an employee’s laptop bag was stolen, including the theft of unencrypted backup media containing names, addresses, Social Security numbers, insurance information and clinical information for 55,000 current and former patients.

According to OCR, a subsequent investigation of the breach found that “Cancer Care was in widespread non-compliance with the HIPAA Security Rule.” The practice failed to conduct an enterprise-wide risk analysis at the time of the breach, and it also did not have a written policy in place regarding the removal of hardware and electronic media containing ePHI into and out of its facilities.

“Organizations must complete a comprehensive risk analysis and establish strong policies and procedures to protect patients’ health information,” OCR Director Jocelyn Samuels said in a statement. “Further, proper encryption of mobile devices and electronic media reduces the likelihood of a breach of protected health information.”

Cancer Care has taken corrective action with regard to the specific requirements of the Privacy and Security Rules that are at the core of this enforcement action, as well as actions to come into compliance with the other provisions of the HIPAA rules, according to OCR.

Sponsored Recommendations

Care Access Made Easy: A Guide to Digital Self-Service for MEDITECH Hospitals

Today’s consumers expect access to digital self-service capabilities at multiple points during their journey to accessing care. While oftentimes organizations view digital transformatio...

Going Beyond the Smart Room: Empowering Nursing & Clinical Staff with Ambient Technology, Observation, and Documentation

Discover how ambient AI technology is revolutionizing nursing workflows and empowering clinical staff at scale. Learn about how Orlando Health implemented innovative strategies...

Enabling efficiencies in patient care and healthcare operations

Labor shortages. Burnout. Gaps in access to care. The healthcare industry has rising patient, caregiver and stakeholder expectations around customer experiences, increasing the...

Findings on the Healthcare Industry’s Lag to Adopt Technologies to Improve Data Management and Patient Care

Join us for this April 30th webinar to learn about 2024's State of the Market Report: New Challenges in Health Data Management.