Cyber Security: A Wake-Up Call from Syracuse ASC’s HIPAA Violation

In today’s digital age, cybersecurity isn’t just an IT issue; it’s a critical component ofbusiness operations, especially in sectors handling sensitive information. The recentResolution Agreement between the Department of Health and Human Services (HHS)and Syracuse ASC, L.L.C., a specialty surgery center in Central New York, serves as astark reminder of the potential consequences of neglecting …

Healthcare Provider Fined After HIPAA Violations: A Wake-Up Call for Cybersecurity

In today’s digital age, the healthcare industry is more reliant on technology than everbefore. This reliance, however, comes with significant risks, especially concerning thesecurity of sensitive patient data. A recent resolution agreement between theDepartment of Health and Human Services (HHS) and Deer Oaks—The BehavioralHealth Solution serves as a stark reminder of the importance of robust …

HHS OCR Imposes a Civil Monetary Penalty on Essex Residential Care for Failing to Provide Timely Access to Patient Records

Hackensack Meridian Health and West Caldwell Care Center (WCCC) have been issued a final civil money penalty (CMP) of $100,000 by the Office for Civil Rights (OCR). The OCR has the authority to impose this penalty under the Health Insurance Portability and Accountability Act of 1996 (HIPAA). WCCC has chosen not to contest the findings …

Snooping in Medical Records

Yakima Valley Memorial Hospital has settled with the U.S. Department of Health and Human Services’ Office for Civil Rights (OCR) for $240,000 after security guards accessed medical records without authorization. The hospital will update policies and procedures to protect patient information and train employees to prevent future breaches. OCR Director Melanie Fontes Rainer stressed the …

Disclosure of Patients’ Protected Health Information to a News Reporter

St. Joseph’s Medical Center has settled with the Office for Civil Rights (OCR) over a HIPAA investigation regarding the disclosure of patients’ protected health information to a news reporter. The medical center provided a national media outlet with access to COVID-19 patients’ information without obtaining written authorization. OCR determined that three patients’ information was disclosed, …

HHS’ Office for Civil Rights Settles Ransomware Cyber-Attack Investigation

The U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR) has settled a ransomware cyber-attack investigation with Doctors’ Management Services, a Massachusetts medical management company. The $100,000 settlement resolves a breach report regarding a ransomware attack that affected the health information of over 200,000 individuals. Doctors’ Management Services will be monitored …

UnitedHealthcare Settles $80,000 with HHS to Resolve HIPAA Concerns Regarding Patient Medical Records Request

UnitedHealthcare Insurance Company (UHIC) has reached a settlement with the Office for Civil Rights (OCR) at the U.S. Department of Health and Human Services (HHS) over a potential violation of the HIPAA Privacy Rule’s right of access provision. UHIC agreed to pay $80,000 and implement a corrective action plan. This is the 45th Right of …

HHS settles $75,000 HIPAA case with iHealth Solutions over Unsecured Server Disclosure

The HHS Office for Civil Rights has settled a HIPAA investigation with iHealth Solutions for $75,000. iHealth Solutions, a business associate, experienced a data breach affecting 267 individuals when a network server containing protected health information was left unsecured on the internet. The investigation found evidence of potential failures by iHealth Solutions to analyze risks …

HIPAA Enforcement Action: Dr. U. Phillip Igbinadolor, D.M.D. & Associates, P.A. (UPI)

From the HHS web site: “Dr. U. Phillip Igbinadolor, D.M.D. & Associates, P.A. (UPI), a dental practice with offices in Charlotte and Monroe, North Carolina, impermissibly disclosed a patient’s PHI on a webpage in response to a negative online review.  UPI did not respond to OCR’s data request, did not respond or object to an …

HIPAA Enforcement Action: Dr. Donald Brockley, D.D.M.

From the HHS site: “Dr. Donald Brockley, D.D.M., a solo dental practitioner in Butler, Pennsylvania, failed to provide a patient with a copy of their medical record.  After being issued a Notice of Proposed Determination, Dr. Donald Brockley, D.D.M requested a hearing before an Administrative Law Judge.  The litigation was resolved before the court made …