1 min read

Memorial Healthcare Systems fined for lack of audit controls

Memorial Healthcare Systems hospital building exterior

Memorial Healthcare Systems has paid the U.S Department of Health and Human Services $5.5 million as a result of violations of the Health Insurance Portability and Accountability act of 1996. Memorial Healthcare Systems manages six hospitals, an urgent care center and an elderly facility within South Florida.

Memorial Healthcare Systems building in South Florida

Between April 2011 and April 2012 the login credentials of an old employee were used by staff members to access and distribute ePHI affecting over 80,000 individuals. The data that was distributed included names, dates of birth and social security numbers. MHS had loose policies in place for employee’s access to protected health information however they failed to implement structural safeguards and audit controls to monitor who can access protected health information. MHS failure to regularly monitor employee activity within their system ultimately led to their breach. If they had implemented proper audit controls MHS could have had prevented unauthorized access to its patient’s information. Audit controls maintain a system of record of all application processes and system activity by individual users. Having audit controls in place allows covered entities to review inappropriate access, detect potential breaches and malicious activity, and provide evidence during investigations.

 

Summary of HIPAA Fines

  • Providing access of protected health information of over 80,000 individuals
  • Failure to report breach of ePHI in a timely fashion.
  • Failure to implement audit controls to monitor system activity
  • Failure to implement the correct policies and procedures to prevent, detect and handle security breaches

 

Try Paubox Email Suite for FREE today.
Doctor's white coat with stethoscope and medical instruments

ONC federal health IT strategy focuses on privacy and security

The Department of Health and Human Services (HHS) recently shared its draft Federal Health IT Strategy for 2020-2025 , developed in partnership with...

Read More
graphic of files coming out of a paper folder onto a laptop computer

HIPAA compliant file sharing

Unlike standard file-sharing practices, which might not prioritize data security, HIPAA compliant methods ensure that sensitive health information...

Read More

Subscribe to Paubox Weekly

Every Friday we bring you the most important news from Paubox. Our aim is to make you smarter, faster.