ALJ Judge Upholds OCR’s $4,348,000 Data Breach Penalty on Texas Hospital

Harris Beach Murtha PLLC
Contact

HIPAA has teeth.  On June 1, 2018, an Administrative Law Judge (ALJ) ruled that the University of Texas MD Anderson Cancer Center violated HIPAA.  In doing so, the ALJ granted the Office of Civil Rights (OCR) summary judgment, requiring the hospital to fork up the $4,348,000 in civil monetary penalties imposed by OCR. 

The underlying facts of this data breach involved the theft of an unencrypted laptop from a physician’s home and the loss of two unencrypted thumb drives.  Combined, this theft and loss compromised the PHI of 33,500 individuals. To make matters worse, upon investigating the breaches, OCR uncovered that the hospital’s own risk analyses, as far back as 2006, found that the Hospital’s lack of device-level encryption was a high risk.  Unfortunately, the hospital did not act on the risk, failing to encrypt its inventory of electronic devices containing PHI.

The important lessons learned here are twofold.  First, take the risks identified by risk analyses seriously.  More importantly, why HIPAA is scalable, entities should try to implement some measures to address the associated risks identified by the analyses.  Second, all covered entities and business associates should ensure that they encrypt portable media devices.  Unfortunately, theft happens and small USB drives are lost or misplaced.  For when the inevitable happens, encryption is one of your best defenses.

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations. Attorney Advertising.

© Harris Beach Murtha PLLC

Written by:

Harris Beach Murtha PLLC
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

Harris Beach Murtha PLLC on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide