In a time when EHR security is still catching up to the abilities of malevolent hackers, it only makes sense that the U.S. Department of Health & Human Services (HHS) Office for Civil Rights (OCR) will do anything it can to get covered entities and business associates to actually take their security seriously. If that means fining a single covered entity $1.5 million, the maximum annual amount , to settle long-standing noncompliance HIPAA violations in order to send out a warning signal of what won’t be tolerated, then so be it. That is exactly what happened to Athens Orthopedic Clinic, an Athens, GA-based healthcare facility that was founded in 1966. It provides orthopedic services to roughly 130,000 patients a year.
What happened
On June 26, 2016, data hacking journalist Dissent from Databreaches.net (regular readers of this blog will remember this individual from the Blackbaud incident ) notified the clinic about protected health information (PHI) that had been posted on the dark web for sale. After an initial investigation, Athens Orthopedic Clinic discovered that hackers from the notorious international hacking organization known as The Data Overlord had obtained credentials for access into the third party vendor system that contained patient data on June 14th, 2016. Over the next month, until July 16th, the hacking group continued to access the clinic’s PHI. A breach report filed by the clinic to the OCR showcased that 208,557 individuals had been affected and information like names, birthdays, social security numbers, medical procedures, test results, and healthcare insurance information had been extracted from the database.What a further investigation uncovered
Suffice it to say, this was one of the more notorious covered entity hacking events in a long time. When the OCR investigated further , it uncovered longstanding systemic noncompliance by Athens Orthopedic Clinic of HIPAA rules and policies including:- Failure to conduct a software implementation risk analysis
- No implementation of risk management
- No implementation of audit controls
- Failure to maintain HIPAA policies and procedures
- Failure to secure business associate agreements (BAA’s) with multiple business associates
- No HIPAA Privacy Rule training for workforce members
