Healthcare provider pays hefty settlement for HIPAA noncompliance
Last week, the Office for Civil Rights (OCR) released a statement regarding its settlement with the practice of Steven A. Porter, M.D. (the Practice)...
The U.S. Department of Health and Human Services (HHS) Office for Civil Rights’ (OCR) HIPAA enforcement continues during the pandemic. This year, OCR has already settled with three covered entities (CEs) following investigations into their reported breaches. Such settlements remind healthcare organizations of the importance of HIPAA compliance and strong cybersecurity even during health crises.
| Porter, M.D. | Metro | Lifespan | |
| Date breach filed | 2013 | 2011 | 2017 |
| Date settled in 2020 | March 3 | July 23 | July 27 |
| Fee | $100,000 | $25,000 | $1.04 million |
| Misc. penalty | Corrective plan | Corrective plan | Corrective plan |
| # affected individuals | 500 | 1,263 | 20,431 |
| Type of breach | Improper disposal | Phishing | Theft of laptop |
| Why a violation | · No risk analysis conducted · Failed to implement security measures | · No risk analysis conducted · Did not adhere to Security Rule · Did not provide training until 2016 | · Failure to encrypt · Lack of media/device controls · Absence of a business associate agreement (BAA) |
Last week, the Office for Civil Rights (OCR) released a statement regarding its settlement with the practice of Steven A. Porter, M.D. (the Practice)...
In 2023, the Office for Civil Rights (OCR) settled numerous cases with healthcare organizations for potential HIPAA violations. These violations...
The U.S. Health and Human Services’ (HHS) Office for Civil Rights (OCR) has appointed a new director, Lisa J. Pino. Originally from New York City,...
Every Friday we bring you the most important news from Paubox. Our aim is to make you smarter, faster.