Recently, the Office for Civil Rights (OCR) at the U.S. Department of Health and Human Services (HHS), the agency enforcing the Health Insurance Portability and Accountability Act (HIPAA) Privacy, Security, and Breach Notification Rules, obtained two large breach-related settlements: one from a HIPAA Covered Entity and one from a HIPAA Business Associate. These enforcement actions signal that despite COVID-19 related challenges, organizations continue to face rampant data breaches and ensuing HIPAA enforcement.
On September 25, 2020, OCR settled an investigation into a breach suffered by a large health insurer by obtaining the second-largest resolution payment in HIPAA enforcement history ($6.85 million). This enforcement action resolved an investigation concerning potential violations of HIPAA Privacy and Security Rules related to a breach affecting the electronic protected health information (ePHI) of more than 10.4 million people. The breach resulted from a phishing attack that introduced malware into the insurer’s IT systems and allowed unauthorized actors to gain access and remain undetected for nearly nine months. Similarly on September 23, 2020, a business associate providing IT and health information management services to hospitals and physicians clinics entered a settlement ($2.3 million) with OCR for potential violations of HIPAA Privacy and Security Rules related to a breach affecting over 6 million people. Essentially, these cyberattacks were advanced persistent threats that compromised the privacy and security of ePHI and PHI and revealed longstanding gaps in the companies’ cybersecurity controls.
Blog Editors
Recent Updates
- New Proposed Federal Legislation Takes Aim at Concerns Regarding Perceived “Looting” of Health Care Systems by Private Equity Investors
- Podcast: The Future of Laboratory Testing Just Got a Little Clearer - FDA's Final Rule on LDTs – Diagnosing Health Care
- How Does the End of Chevron Deference Change the Relationship Between the Health Care Industry, Federal Regulators, and Congress?
- Podcast: Down Goes Chevron: A 40-Year Precedent Overturned by the Supreme Court – Diagnosing Health Care
- Thoughts: AB 3129 Expands Its Reach