X
5.5 Million Dollars HIPAA Settlement Shines Light on the Importance of Audit Controls
Collapse
-
5.5 Million Dollars HIPAA Settlement Shines Light on the Importance of Audit Controls
5.5 Million Dollars HIPAA Settlement Shines Light on the Importance of Audit Controls
February 18, 2017
Washington, DC - - (February 16, 2017) - - Memorial Healthcare Systems (MHS) has paid the U.S. Department of Health and Human Services (HHS) $5.5 million to settle potential violations of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy and Security Rules and agreed to implement a robust corrective action plan. MHS is a nonprofit corporation which operates six hospitals, an urgent care center, a nursing home, and a variety of ancillary health care facilities throughout the South Florida area. MHS is also affiliated with physician offices through an Organized Health Care Arrangement (OHCA).
MHS reported to the HHS Office for Civil Rights (OCR) that the protected health information (PHI) of 115,143 individuals had been impermissibly accessed by its employees and impermissibly disclosed to affiliated physician office staff. This information consisted of the affected individuals’ names, dates of birth, and social security numbers. The login credentials of a former employee of an affiliated physician’s office had been used to access the ePHI maintained by MHS on a daily basis without detection from April 2011 to April 2012, affecting 80,000 individuals. Although it had workforce access policies and procedures in place, MHS failed to implement procedures with respect to reviewing, modifying and/or terminating users’ right of access, as required by the HIPAA Rules. Further, MHS failed to regularly review records of information system activity on applications that maintain electronic protected health information by workforce users and users at affiliated physician practices, despite having identified this risk on several risk analyses conducted by MHS from 2007 to 2012.
“Access to ePHI must be provided only to authorized users, including affiliated physician office staff” said Robinsue Frohboese, Acting Director, HHS Office for Civil Rights. “Further, organizations must implement audit controls and review audit logs regularly. As this case shows, a lack of access controls and regular review of audit logs helps hackers or malevolent insiders to cover their electronic tracks, making it difficult for covered entities and business associates to not only recover from breaches, but to prevent them before they happen.”
Information source: U.S. Department of Health and Human ServicesPosting comments is disabled.
Trending
Collapse
Topics | Statistics | Last Post | ||
---|---|---|---|---|
Federal Trade Commission to Crack Down on Companies that Illegally Surveil Children Learning Online
by OverSeer
Started by OverSeer, 05-21-2022, 12:30 PM
|
0 responses
0 views
0 likes
|
Last Post
![]()
by OverSeer
05-21-2022, 12:30 PM
|
||
Started by OverSeer, 05-20-2022, 12:10 PM
|
0 responses
0 views
0 likes
|
Last Post
![]()
by OverSeer
05-20-2022, 12:10 PM
|
||
IRS Provee Guía para que Residentes de Puerto Rico reclamen Crédito Tributario por Niños
by OverSeer
Started by OverSeer, 05-20-2022, 12:10 PM
|
0 responses
0 views
0 likes
|
Last Post
![]()
by OverSeer
05-20-2022, 12:10 PM
|
||
Started by OverSeer, 05-20-2022, 12:10 PM
|
0 responses
0 views
0 likes
|
Last Post
![]()
by OverSeer
05-20-2022, 12:10 PM
|
||
Started by Staff Reporter 1, 05-19-2022, 07:56 AM
|
0 responses
3 views
0 likes
|
Last Post
![]() |
Related Topics
Collapse
Latest Articles
Collapse
Shop Low Cost Domains
Collapse
CNG Vehicle Cost Calculator
Collapse
Air Quality Conditions in Rome, GA Zip Code 30161
Collapse
Trending
Collapse
There are no results that meet this criteria.
Categories
Collapse
Air Quality Conditions in Albuquerque, NM Zip Code 87121
Collapse
Shop at Low Cost Domains
Collapse
Air Quality Conditions in Harrisburg, PA Zip Code 17104
Collapse
Electric Drive Cost Calculator
Collapse