OCR Announces HIPAA Security Settlement with Cancer Care Group, P.C.

Tucker Arensberg, P.C.
Contact

In September, 2015, OCR and HHS issued a press release announcing a Resolution Agreement with the Cancer Care Group, P.C., which included entry into the agreement, the adoption of a robust compliance plan, and the payment of a $750,000 penalty. The settlement arose out of an incident involving the theft of an employee laptop containing unencrypted PHI.

Providers and practitioners generally understand that HIPAA doesn’t require a guarantee of absolute privacy and security, but it absolutely requires good faith efforts to protect PHI. OCR emphasized that the most significant aspect of this situation was that CCG was a widespread non-compliance with the HIPAA security rule, because it had not conducted an enterprise risk analysis and it did not have written policies regarding hardware and removing hardware and electronic media containing PHI from its facilities, even though it was aware or should have been aware that this was a widespread practice.

As a reminder, please be aware that HHS and the Office of the National Coordinator for Health Information Technology (ONC) has published a security risk assessment tool.

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Tucker Arensberg, P.C. | Attorney Advertising

Written by:

Tucker Arensberg, P.C.
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

Tucker Arensberg, P.C. on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide