1 min read

University of Mississippi Medical Center pays $2.75M HIPAA fine

University of Mississippi Medical Center logo

The University of Mississippi Medical Center (UMMC) has agreed to pay an astounding $2.75M fine to settle multiple HIPAA violations. This is the second multi-million dollar HIPAA fine so far this month.

The HIPAA investigation of UMMC occurred due to a breach of electronic protected health information (ePHI) that affected about 10,000 people. The breach was due to a stolen laptop. Because the laptop had a generic username and password, the laptop allowed an unauthorized party access to their network drives. These drives contained ePHI of approximately 10,000 patients. The HIPAA investigation also discovered that due to the widespread use of generic username and passwords, unauthorized users could easily join UMMC's wireless network and immediately access the same network drives.

Further HIPAA violations included:

  • Failure to implement its policies and procedures to prevent, detect, contain, and correct security violations
  • Failure to implement physical safeguards for all workstations that access ePHI to restrict access to authorized users
  • Failure to assign a unique user name and/or number for identifying and tracking user identity in information systems containing ePHI
  • Failure to notify each individual whose unsecured ePHI was reasonably believed to have been accessed, acquired, used, or disclosed as a result of the breach.

About Paubox Paubox is the easiest way to send and receive secure, HIPAA compliant email.

 

Try Paubox Email Suite for FREE today.
Paubox HIPAA Breach Report logo

Lifespan health system pays over $1M for HIPAA breach

On April 21, 2017, Lifespan Corporation filed a breach report with the Office for Civil Rights ( OCR) at the U.S. Department of Health and Human...

Read More
Paubox HIPAA Breach Report logo

HealthEquity, Inc. suffers HIPAA email breach

On June 12, 2018, HealthEquity, Inc. submitted a HIPAA Email Breach to the U.S. Department of Health and Human Services (HHS). Located in Draper,...

Read More
Advocate Health Care logo

Advocate Health Care settles potential HIPAA penalties for $5.55 million

Advocate Health Care Network agreed to a record $5.5 million settlement with the U.S. Department of Health and Human Services, Office for Civil...

Read More

Subscribe to Paubox Weekly

Every Friday we bring you the most important news from Paubox. Our aim is to make you smarter, faster.