Why is the OCR Not Issuing More HIPAA Fines?
The Department of Health and Human Services’ Office for Civil Rights is tasked with policing HIPAA, and there has been no shortage of HIPAA violations of late, so why is the OCR not issuing more HIPAA fines? Huge Data Breaches – Numerous HIPAA Violations – 22 Financial Penalties Since October 2009, 1,140 data breaches affecting more than 500 individuals were reported to the OCR, while there were more than 120,000 breaches involving fewer than 500 individuals. Out of those incidents – including a large number that involved or directly resulted from HIPAA violations – only 22 have warranted OCR HIPAA penalties according to research conducted by ProPublica. The OCR has been reserving financial penalties for organizations that “have involved systemic and/or long-standing”, and is cautious about exercising its rights and fining HIPAA violators. Interestingly, the California Department of Public Health is more active when it comes to holding healthcare organizations accountable for their lack of attention to HIPAA legislation. It too has issued 22 fines to HIPAA...
Up to 18.8M Non-Customers Also Affected By Anthem Data Breach
Anthem has issued a statement confirming it is not only its own customers that have been affected by the mega data breach it suffered, but also between 8.8 million and 18.8 million individuals who are members of Blue Cross Blue Shield health plans of other insurers. According to Reuters, this is the first time that Anthem Inc. has announced that the customers of different insurance companies may also have been compromised in the cyber attack. Anthem is a member of an insurance network that runs Blue Cross Blue Shield plans, and customers signing up for these health plans are able to obtain medical services via any of the hospitals or medical centers signed up for the plan. BCBS covers 105 million Americans and is operated by 37 different healthcare providers. Anthem runs healthcare plans in 14 states under Blue Cross Blue Shield and is the country’s second-largest healthcare insurer. Because of this association, Anthem held data of patients belonging to BCBS health plans provided by other insurers, and that data, it would appear, could have been obtained by hackers. The original...
HIPAA and ISPP Violations Cited in Aventura Hospital Damages Lawsuit
The Aventura HIPAA breach, identified in June last year, has resulted in a lawsuit being filed by a patient of the hospital, according to a Courthouse News Service report. The lawsuit was filed by Aventura patient, Kellie Lynn Case, in the Miami Federal Court. She is seeking damages from the defendants, Hospital Corporation of America and Envision Healthcare Corporation, after they were provided with confidential patient data and failed to implement the appropriate controls to keep that data safe. The lawsuit alleges that the defendants have violated the HIPAA Security Rule in addition to Industry Standard Protection Protocols. Under HIPAA regulations healthcare providers are not permitted to share confidential patient data without having first obtained consent to do so from the patients. They are also required to produce notices of privacy practices which must detail how the data they hold will be used, to whom it will be disclosed and under what circumstances that will happen. The lawsuit alleges that the defendants used the Notice of Privacy Practices as a means to justify an...
2014 Saw 25% Increase in HIPAA Breaches
Redskin has released its 5th annual report of HIPAA breaches reported to the Secretary of Health & Human Services’ Office of Civil Rights (OCR). According to the report there were 164 PHI breaches reported during 2014 which affected approximately 9 million Americans. The data shows there has been a 25% increase in breaches compared to 2013. Last year’s data breaches – including the CHS breach which exposed the data of 4.5 million patients – brings the number of breach victims since the passing of the HITECH Act to over 40 million, although this figure has now potentially been tripled following the Anthem mega breach reported earlier this month. This year’s breach ranks as one of the all time biggest data breaches ever recorded, eclipsing the previous largest healthcare data breaches by many orders of magnitude. To give a better idea of scale, it exposed almost 6 times the data of the huge Tricare breach in 2011, the Community Health System of 2014 and Advocate Medical Group’s HIPAA breach in 2009, which exposed 4.9 million and 4.5 million and 4,029,530 records respectively....
Hospital Employee Receives 18 Month Jail Term for HIPAA Violations
Accessing the healthcare data of patients without authorization is prohibited under HIPAA legislation, and the disclosure of this information to a third party is a criminal matter. The offense carries a jail term of up to 10 years in addition to a maximum fine of $500,000 if the disclosure is made for personal gain. One of the latest examples of wrongful disclosure of individually identifiable health information comes from the Eastern District of Texas where former Longview resident, Joshua Hippler, 30 has been convicted this offence and sentenced to serve 18 months in jail. Hippler was a former employee of an East Texas hospital where he was alleged to have accessed Protected Health Information with the intention of selling it on for personal gain. Hippler was indicted by a federal grand jury on Mar. 26, 2014 and the case was heard by United States Magistrate Judge John D. Love on August 28, 2014. Hippler pleaded guilty to the offenses that took place at an unnamed East Texas hospital between December 1, 2012 and January 14, 2013. The U.S. Department of Health and Human Services’...



