Texas-based cancer hospital agrees to $4.3 million HIPAA settlement

June 20, 2018

On June 18, 2018, the U.S. Department of Health and Human Services, Office for Civil Rights (OCR) announced a settlement with The University of Texas MD Anderson Cancer Center (MD Anderson) for data breaches that potentially disclosed the health records of nearly 35,000 patients. The settlement is the fourth-largest ever paid to OCR. MD Anderson submitted three breach reports in 2012 and 2013, leading to an OCR investigation. The breaches involved the theft of an unencrypted laptop from the home of an MD Anderson employee and the loss of two unencrypted USB thumb drives containing the electronic protected health information (ePHI) of MD Anderson patients.

OCR found that MD Anderson had written encryption policies in place going as far back as 2006 and that it had conducted internal risk analyses that had previously determined that the lack of device-level encryption posed a high risk to the security of ePHI. Despite this information, OCR found that MD Anderson did not begin to adopt an enterprise-wide solution to implement encryption of ePHI until 2011 and even then it failed to encrypt its inventory of electronic devices containing ePHI between March 24, 2011 and January 25, 2013—the time period during which the breaches occurred.

OCR proposed, and received, the maximum financial penalty against MD Anderson for a “Tier 2” HIPAA violation—a minimum of $1,000 for each violation up to a maximum of $1.5 million per calendar year. Tier 2 describes situations in which an “act or omission in which a covered entity or business associate knew, or by exercising reasonable diligence would have known, that the act or omission violated an administrative simplification provisions, but in which the covered entity or business associate did not act with willful neglect.”

Lexology has the full article

Sponsored Recommendations

Enhancing Healthcare Through Strategic IT and AI Innovations

Learn how strategic IT and AI innovations are transforming healthcare - join Tomas Gregorio as he explores practical applications that enhance clinical decision-making, optimize...

The Intersection of Healthcare Compliance and Security in the Age of Deepfakes

As healthcare regulations struggle to keep up with rapid advancements in AI-driven threats like deepfakes, the security gaps have never been more concerning.

Increasing Healthcare Security Behind and Beyond the Firewall

Read how 5 identity security solutions can help you protect against these threats while improving user experience and reducing costs.

Improve and Secure Healthcare Delivery with Digital Identity

Get a deep understanding of how Digital Identity can help secure your healthcare organization while offering seamless access to your growing portfolio of apps and APIs.