Hacked Business Associate Agrees to Pay $100,000 as Part of HIPAA Settlement

Saul Ewing LLP
Contact

Saul Ewing Arnstein & Lehr LLP

On May 23, 2019, the U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR), announced that Medical Informatics Engineering, Inc. (MIE) agreed to pay $100,000 to settle alleged HIPAA violations that exposed the protected health information (PHI) of more than 3,500,000 individuals when hackers accessed its servers in an unauthorized manner.

MIE is a HIPAA business associate based in Indiana that provides software and electronic medical record services to health care providers.

According to the OCR press release announcing MIE’s settlement, MIE filed a HIPAA breach report in July, 2015 “following discovery that hackers used a compromised user ID and password to access the electronic protected health information (ePHI) of approximately 3.5 million people.”

In addition to the $100,000 payment, MIE entered into a two-year corrective action plan (CAP) with HHS.  As part of the CAP, MIE agreed to:

  • Conduct a comprehensive risk analysis of “the potential risks and vulnerabilities to the confidentiality, integrity, and availability” of MIE’s ePHI within 30 days of the effective date of the OCR settlement.  OCR specified MIE’s risk analysis shall include an inventory of its facilities and categories of electronic equipment;
  • Develop and implement a written risk management plan to address and mitigate security risks and vulnerabilities identified in the risk analysis; and
  • Provide annual reports to HHS of its compliance efforts with respect to the CAP.

The MIE settlement highlights the importance of covered entities and business associates conducting thorough risk analyses as required by the Security Rule. MIE is a HIPAA business associate, and so the settlement also serves as a reminder that business associates have direct liability to the government under HIPAA. Hackers are pervasive in the health care delivery system (and across all industries) and MIE’s failure to identify potential risks and vulnerabilities to its ePHI resulted in an expensive settlement for MIE.  

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations. Attorney Advertising.

© Saul Ewing LLP

Written by:

Saul Ewing LLP
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

Saul Ewing LLP on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide