Triple S Salud Hit with Record $6.8 Million Fine for HIPAA Breach
Violations of the Health Insurance Portability and Accountability Act (HIPAA) can carry heavy financial penalties and the U.S. Department of Health and Human Services’ Office for Civil Rights has already issued fines of up to $1.9 million dollars for security breaches and HIPAA non-compliance issues. However, Puerto Rican Insurer Triple S Salud revealed yesterday that it has been hit with a record breaking $6.8 million fine for breaching HIPAA regulations and exposing the data of thousands of beneficiaries of its Dual Eligible Medicare plan. The Puerto Rico Health Insurance Administration submitted an 8-K filing after the discovery of the security breach, with Triple S Salud being notified of its intentions to apply a financial penalty for the HIPAA violation earlier this month. New sanctions will also be imposed which require the insurer to notify all individuals potentially affected by the breach and also advise them of their right to leave the program. It must also suspend new enrollments to the Dual Eligible Medicare plan. HIPAA violations investigated by the OCR have resulted...
HIPAA Breach at Froedtert Health Exposes 43,000 Patient Records
Milwaukee based healthcare provider, Froedtert Health, has announced that it has suffered a data breach that could potentially have affected up to 43,000 patients as a result of a computer virus which had infected an employee’s PC. Froedtert Health operates a three-hospital system comprising of the Froedtert Hospital in Milwaukee, St. Joseph’s Hospital in West Bend and Community Memorial Hospital in Menomonee Falls. Patients from all three hospitals have been affected and breach notification letters were sent earlier this week. The virus was discovered on December 14, 2013 and it is understood that it could potentially have allowed hackers to gain access to the Protected Health Information – and personal identifiers – stored in the employee’s work computer account. In a statement announcing the breach, Froedtert Health explained that it enlisted the help of a computer forensics company to conduct an investigation to determine the extent of the infection and whether it constituted a HIPAA breach. The forensics company was unable to establish whether hackers had actually...
HIPAA Compliance: A Model for all Businesses
The Health Insurance Portability and Accountability Act (HIPAA) was introduced in 1996 in order to set minimum standards for healthcare insurance, with the legislation also covering the safe storage of electronic healthcare data of patients. All entities covered under HIPAA, as well as their business associates, must take appropriate measures to ensure that the Protected Health Information of patients cannot be accessed by unauthorized individuals. In order for a healthcare organization to be HIPAA compliant, a number of policies and procedures must be introduced. All systems and servers must be assessed for security risks, data must be stored securely, backed up and a disaster recovery plan should be documented so that in the event that data is lost, corrupted or stolen it can be easily recovered. A standard contingency plan must be devised and a number of documents created to confirm that HIPAA regulations have been addressed. The documentation must cover the back up of data, include a detailed disaster recovery plan and there must also be procedures documented for operating in...
Data Encryption Advisable but not Mandatory Under HIPAA
Healthcare organizations must take steps to prevent confidential patient health data from being viewed, accessed or used by unauthorized individuals, although current HIPAA regulations do not require healthcare organizations – or their business associates – to encrypt PHI data. However, according to the Director of the Office for Civil Rights, Leon Rodriguez, it is strongly advisable. The HIPAA data breach rule requires healthcare organizations to report any loss of laptop or mobile device containing patient data as a HIPAA breach since the introduction of the HITECH Act (2009); however the loss is not reportable if the data on the device has been encrypted (provided the data encryption is in accordance with the guidance issued by the National Institute of Standards and Technology). According to Rodriguez, in all cases of laptop or computer theft reported to date, financial penalties would have been avoided if the data contained on the lost/stolen devices had been encrypted. Following a data breach, HIPAA covered entities are required to notify all individuals affected by the...
HIPAA Omnibus Rule Final Release Issued
The HIPAA Omnibus Rule (Health Insurance Portability and Accountability Act of 1996 Omnibus Rule) was drafted in July 2010; however the final release has been delayed until this month in order to address some of the concerns raised by stakeholders about the latest HIPAA amendment. The final rule has been held by the Office of Management and Budget since March last year although the final release has now been issued. All HIPAA-covered entities – and their business associates – must read the new rule and make changes to existing policies and procedures and factor in the new amendments. Healthcare organizations have 180 days in order to effect the changes as the Final Rule will not be enforced until Sept 22, 2013. The new rule has been issued to bring HIPAA in line with HITECH, and was introduced by the U.S. Department of Health and Human Services’ Office of Civil Rights to cover the use of Health Information Technology (HIT) and ensure that patient health information is properly protected. The final rule represents a major change to the legislation and is the most extensive...



