25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Massachusetts Dermatology Clinic Settles for $150K over HIPAA Breach

The Office for Civil Rights has issued a statement confirming that an agreement has been reached with Adult & Pediatric Dermatology, P.C., of Concord, Massachusetts following the accidental disclosure of approximately 2,200 patients after a memory stick was stolen from the car of one of the center’s employees. The stolen thumb drive contained patient data and was not encrypted, meaning anyone in possession of the storage device has full access to the data it contained. The missing thumb drive has so far not been located.

Although the HIPAA breach involved a relatively small number of patients, the OCR has fined the dermatology clinic $150,000 for violating HIPAA regulations and failing to ensure the PHI of its patients was properly secured. The OCR has also ordered the clinic to conduct a full risk analysis to identify any remaining privacy and security issues and to develop a risk management plan to deal with any future security breaches.

The investigation conducted by the OCR highlighted a number of HIPAA privacy and security problems which should have been identified and addressed had a thorough risk analysis been conducted. The OCR also determined that the clinic had failed to implement the changes required under the HITCH Act (2009). While breach notification rules were followed, the legislation also requires a HIPAA covered entity to document data security procedures and policies as well as provide staff training on data security and privacy. This is the first time that the OCR has issued fines for policy and procedural failures regarding HIPAA breach notification rules.

This case has demonstrated that it is not only data breaches that can result in fines being issued, but also a failure to document policies and procedures. It is not sufficient for a healthcare organization to follow only some HIPAA security rules such as issuing a breach notification and all HIPAA policies must be followed to the letter. The OCR is of the opinion that a failure to adhere to all aspects of HIPAA is negligence, and when there is negligence financial penalties are certain to follow.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The OCR investigates all HIPAA breaches and if it is discovered that the security breach resulted from a failure to adhere to HIPAA guidelines, fines of up to $50,000 can be applied for each violation up to a total of $1.5 million.

This settlement should send a message to other healthcare organizations alerting them to the importance of conducting a full risk analysis of all IT systems, which should include any device or equipment that comes into contact with electronic protected health information. Mobile devices such as laptop computers, tablets, Smartphones must be secured, and any data stored on a hard drive, thumb drive or other digital storage medium must have ePHI data encrypted to prevent accidental exposure if the device is lost, stolen or improperly accessed.

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist