HIPAA Compliance News

$475,000 Settlement for Delayed HIPAA Breach Notification

The Department of Health and Human Services’ Office for Civil Rights (OCR) has announced the first HIPAA settlement of 2017. This is also the first settlement to date solely based on an unnecessary delay to breach notification after the exposure of patients’ protected health information. Presence Health, one of the largest healthcare networks serving residents of Illinois, has agreed to pay OCR $475,000 to settle potential HIPAA Breach Notification Rule violations.

Following a breach of PHI, the HIPAA Breach Notification Rule requires covered entities to issue breach notification letters to all affected individuals advising them of the breach. Those letters need to be issued within 60 days of the discovery of the breach, although covered entities should not delay the issuing of breach notifications to patients or health plan members unnecessarily.

Additionally, if the breach affects more than 500 individuals, a breach report must be submitted to Office for Civil Rights within 60 days and the Breach Notification Rule also requires covered entities to issue a breach notice to prominent media outlets. Covered entities should also place a substitute breach notice in a prominent place the company website to alert patients or plan members to the breach.

Smaller breaches impacting fewer than 500 individuals must also be reported to OCR, although covered entities can report these smaller breaches annually within 60 days of the end of the calendar year. Covered entities should note that state data breach laws may not permit such delays and that regardless of the number of individuals impacted by a breach, HIPAA requires patients to always be notified within 60 days of a PHI breach.

Presence Health experienced a breach of physical protected health information (PHI) in late 2013. Operating room schedules had been removed from the Presense Surgery Center at the Presence St. Joseph Medical Center in Joliet, Illinois, and could not be located. The documents contained sensitive data on 836 patients, including names, birth dates, medical record numbers, details of procedures performed, treatment dates, the types of anaesthesia provided, and names of the surgeons that performed operations.

Presence Health became aware that the documents were missing on October 22, 2013, yet OCR was not notified of the breach until January 31, 2014, more than a month after the 60-day HIPAA Breach Notification Rule deadline.

OCR investigates all breaches of more than 500 records – and selected branches of fewer than 500 records. The OCR investigation revealed notification to OCR was issued 104 days after the breach was discovered – 34 days after the deadline for reporting the incident had passed. A media notice was issued, although not until 106 days after the breach was discovered – 36 days after the HIPAA Breach Notification Rule deadline. Patients were notified of the breach 101 days after discovery – 31 days after the HIPAA Breach Notification Rule deadline had passed.

Investigators determined that this was not the only instance where breach notifications to patients had been delayed. Presense Health had experienced a number of smaller PHI breaches in 2015 and 2016, yet for several of those breaches, Presense Health did not provide affected individuals with timely breach notifications.

Announcing the resolution agreement and settlement, OCR Director Jocelyn Samuels said “Covered entities need to have a clear policy and procedures in place to respond to the Breach Notification Rule’s timeliness requirements.” She went on to explain the reason why individuals need to be notified of PHI breaches promptly, saying “Individuals need prompt notice of a breach of their unsecured PHI so they can take action that could help mitigate any potential harm caused by the breach.”

The settlement should serve as a warning to HIPAA covered entities that unnecessary breach notification delays can have serious financial repercussions. 60-days is the maximum time frame for reporting (and announcing) PHI breaches, not a recommendation.

The post $475,000 Settlement for Delayed HIPAA Breach Notification appeared first on HIPAA Journal.

UMass to Pay OCR $650K to Resolve HIPAA Violations

The Department of Health and Human Services’ Office for Civil Rights (OCR) has agreed to a $650,000 settlement with University of Massachusetts Amherst (UMass). The settlement resolves HIPAA violations that contributed to the university experiencing a malware infection in 2013.

In early 2013, malware was installed on a workstation in the Center for Language, Speech, and Hearing. The infection resulted in the impermissible disclosure of the electronic protected health information of 1,670 individuals. Those individuals had their names, addresses, social security numbers, birth dates, health insurance information, diagnoses, and procedure codes disclosed to the actors behind the malware attack.

Following the discovery of the infection in 2013, UMass conducted a detailed analysis of the infected workstation. The malware was a generic remote access Trojan and infection occurred because the workstation was not protected by a firewall. UMass ascertained that access to ePHI had been gained.

OCR investigates all data breaches that impact more than 500 individuals to determine whether breached entities have complied with the HIPAA Privacy, Security, and Breach Notification Rules and whether breaches have occurred as a result of HIPAA violations. According to the resolution agreement, OCR was notified of the breach by UMass on June 4, 2013 and an investigation was launched on August 27, 2013.

OCR investigators discovered a number of areas of non-compliance with HIPAA Rules that directly contributed to the UMass data breach.

As a hybrid entity, UMass is only required to comply with HIPAA Rules for some of its components – Those that meet the definition of a covered entity or business associate under HIPAA definitions. UMass had implemented appropriate safeguards to protect the confidentiality, integrity, and availability of ePHI for its University Health Services component; but those same controls were not used for the Center for Language, Speech, and Hearing as UMass did not designate it as a healthcare component.

According to OCR, “To successfully “hybridize,” the entity must designate in writing the health care components that perform functions covered by HIPAA and assure HIPAA compliance for its covered health care components.”

This error meant that UMass did not conduct a HIPAA-compliant risk analysis at the Center. A risk analysis was eventually performed, but not until September 2015. UMass also failed to implement technical security measures to protect the Center’s network and prevent unauthorized ePHI access.

The HIPAA violations could have resulted in a much higher financial penalty but OCR took the University’s finances into account. OCR said the settlement “is reflective of the fact that the University operated at a financial loss in 2015.”

OCR Director Jocelyn Samuels announced the settlement and explained that “HIPAA’s security requirements are an important tool for protecting both patient data and business operations against threats such as malware,” Samuels went on to say “Entities that elect hybrid status must properly designate their health care components and ensure that those components are in compliance with HIPAA’s privacy and security requirements.”

UMass agreed to the settlement with no admission of liability. UMass will pay a $650,000 penalty and will adopt a corrective action plan (CAP) to ensure policies and procedures are brought in line with the minimum standards required under the Health Insurance Portability and Accountability Act.

The CAP requires UMass to conduct a comprehensive risk analysis of all equipment, systems and applications that are used to access or store ePHI to ensure all risks to the confidentiality, integrity, and availability of ePHI are identified.

An enterprise-wide risk management plan must also be developed to address all risks to ePHI that are identified by the risk analysis. A full review of policies and procedures must also take place to ensure they comply with Federal standards, and all staff members must be provided with training on those policies and procedures after they have been approved by OCR.

The post UMass to Pay OCR $650K to Resolve HIPAA Violations appeared first on HIPAA Journal.