Penalties for Data Breaches Increased Under HIPAA Omnibus Rule
Financial penalties for healthcare organizations found in violation of HIPAA regulations are to be increased substantially as part of the HIPAA Omnibus Rule, which will also be applied to business associates and their subcontractors. The original fine structure was established by the American Recovery and Reinvestment Act of 2009 (ARRA), although no further increases have been made in the following four years. The new tiered financial penalties have been introduced in line with the Health Information Technology for Economic and Clinical Health Act (HITECH) and increase the maximum penalties for each non-compliance offense, in addition to increasing the maximum penalty for repeat violations. Healthcare organizations committing a one-time violation will still receive a maximum penalty of $50,000; however, repeat violations can now see fines of up to $1.5 million issued, with the maximum penalty now applying to all HIPAA violation categories. While willful neglect carries a $50,000 penalty for each violation, a lack of knowledge of HIPAA and its subsequent amendments is not a...
Stolen Laptop Exposes 57K Patients Records in HIPAA Security Breach
Healthcare organizations can take the necessary measures to protect their computer networks from targeted attacks by hackers; however one of the biggest risks to data security comes from mobile devices such as laptop computers, Smartphones and portable storage devices such as external hard drives and memory sticks. Laptops and other mobile devices have become as essential in the healthcare industry as they have become to modern life. Physicians and healthcare professionals can improve the service provided to patients and they allow doctors access to full patient medical histories, where ever the doctor needs to perform the consultation. As useful as they are, great care must be taken to keep the devices secure. Data encryption is the obvious solution along with training the staff on HIPAA regulations and the importance of securing the contained on the portable electronic devices. Failure to secure PHI data is a HIPAA violation and thefts of laptops containing unencrypted data is reportable to the Office of Civil Rights and is likely to result in substantial financial penalties...
Omnicell HIPAA Breach More Extensive than First Feared
The theft of an electronic device from an Omnicell employee’s car was announced on 21st December by the University of Michigan Health System (UMHS) to have caused a HIPAA breach affecting 4000 patients of three of its hospitals. Omnicell has now revealed that the breach also affected approximately 56,000 patients at Sentara Health and the records of 8,500 patients of South Jersey Healthcare were also stored on the stolen device. Sentara Healthcare data related to patients who had visited one of its outpatients clinics or hospitals, although it has now been confirmed that the data is limited to patients of the Sentara CarePlex, Sentara Leigh Hospital, Sentara Norfolk General Hospital, Sentara Obici Hospital, Sentara Princess Anne Hospital, Sentara Virginia Beach General Hospital, Sentara Williamsburg Regional Medical Center, Sentara BelleHarbour, Sentara Independence and Sentara Port Warwick. The records on the device related to visits between Oct 18 and Nov 9, 2012. Sentara Healthcare issued breach notifications to all affected patients advising them that their clinical and...
441-Patient HIPAA Breach Results in 50K Penalty
Under Health Insurance Portability and Accountability Act (HIPAA) regulations, healthcare organizations are required to report data breaches involving more than 500 individuals to the Office of Civil Rights and financial penalties apply for HIPAA violations; however security breaches involving fewer individuals can still result in fines being issued. In 2010, a laptop computer was stolen from a community non-profit hospice in Hayden, North Idaho. The laptop contained the PHI of 441 patients including Social Security numbers, medical test results, diagnoses, medications issued and other protected patient information. The laptop was issued to a nurse from the he Hospice of North Idaho who took the device home with her at the weekend and left it in her car where it was subsequently stolen. When data breaches involve more than 500 patients the incident must be reported to the OCR promptly; however since this incident involved just 441 patients, the report of the theft and data breach was not provided to the OCR until the year end; as required under HIPAA breach notification rules. Upon...
University of Michigan Health System Reports 4000-Patient HIPAA Breach
The University of Michigan Health System (UMHS) has announced that the records of 4000 patients may have been exposed by Omnicell, its supply management system vendor. The data breach affected the patients of three hospitals operated by the University of Michigan Health System, all of whom had visited for consultations between October 24th, 2012 and November 13, 2012. The unencrypted data was stored on an unnamed device that was stolen from a car belonging to an Omnicell employee. This is a violation of the data privacy and security policies in place at UMHS. The lost data was limited to medications prescribed, demographics, and some other health information; although UMHS confirmed that no Social Security numbers or credit card details were compromised in the incident. Names were included but no addresses or phone numbers were present in the data. Pursuant to the Health Insurance Portability and Accountability Act, UMHS is in the process of notifying all individuals affected by the breach in writing to alert them to the possibility that their personal health information could be...



