Stolen Laptops Lead to $2 Million in HHS Fines

From: HealthData Management

The HHS Office for Civil Rights has levied monetary fines and corrective action plans against a provider organization and a health insurer for violations of the HIPAA privacy and security rules.

OCR fined provider organization Concentra Health Services $1,725,220, and fined Arkansas insurer QCA Health Plan Inc. $250,000, with both organizations signing resolution agreements to adopt a corrective action plan for HIPAA compliance. Both organizations demonstrated long-time non-compliance with HIPAA, according to OCR, which has now taken this level of action against at least 20 organizations.

In an announcement titled, “Stolen Laptops Lead to Important HIPAA Settlements,” OCR noted, “These major enforcement actions underscore the significant risk to the security of patient information posed by unencrypted laptop computers and other mobile devices.” Susan McAndrew, deputy director of health information privacy, hammered home the message a third time: “Covered entities and business associates must understand that mobile device security is their obligation. Our message to these organizations is simple: encryption is your best defense against these incidents.”

Read Complete Article

Facebooktwittergoogle_plusredditpinterestlinkedinmail

Leave a Reply

Your email address will not be published.

Please Answer: *