Stolen USB drives continue to generate large HIPAA fines

Featured image

Share this article

As we’ve previously covered, stolen USB drives are a big liability for HIPAA entities. When we last covered it in 2014, we used public data to calculate that it costs an average of $925,000 in HIPAA fines per stolen thumb drive. That average is likely to go up.

This week the U.S. Department of Health and Human Services announced it issued a $2.2 million HIPAA fine for a stolen USB thumb drive. The affected entity is MAPFRE Life Insurance Company of Puerto Rico (MAPFRE).

Stolen USB Drives Continue to Generate Large HIPAA Fines - Paubox

USB drive stolen overnight

On 29 September 2011, MAPFRE filed a breach report with HHS indicating that a USB drive containing ePHI was stolen from its IT department, where the device was left overnight. The USB drive included names, birthdates and Social Security numbers of over 2,200 individuals.

A subsequent investigation by HHS revealed MAPFRE’s noncompliance with HIPAA regulations.

  • Failure to conduct a risk analysis and implement risk management plans, contrary to what was claimed earlier.
  • Failure to deploy encryption on its laptops and removable storage media until three years after the incident.
  • Failure or significant delay in implementing corrective measures.

USB Drives are a HIPAA Violation Waiting to Happen

Our stance on USB drives (thumb drives) remains the same: They do not belong in healthcare and are a HIPAA violation waiting to happen.

Here’s why:

  • They are easy to steal or misplace.
  • Hardware Encrypted USB Drives are hard to distinguish from non-encrypted drives.
  • Using software to encrypt a USB drive is beyond the ability of most users. In other words, they won’t do it.

We believe HIPAA violations like this will further push U.S. healthcare entities to adopt HIPAA compliant cloud storage technologies like Paubox.

About MAPRE

MAPFRE is a subsidiary company of MAPFRE S.A., a global multinational insurance company headquartered in Spain. MAPFRE underwrites and administers a variety of insurance products and services in Puerto Rico, including personal and group health insurance plans.

SEE ALSO: HIPAA Fines caused by Stolen Thumb Drives

Try Paubox Email Suite for FREE today.
Author Photo

About the author

Hoala Greevy

Founder of Paubox. Kayak fishing when I can. Native Hawaiian CEO.

Read more by Hoala Greevy

Get started with
end-to-end protection

Bolster your organization’s security with healthcare’s most trusted HIPAA compliant email solution

The #1-rated email encryption 
and security software on G2

G2 Badge: Email Encryption Leader Fall 2022
G2 Badge: Security Best Usability Fall 2022
G2 Badge: Encryption Momentum Leader Fall 2022
G2 Badge: Security Best Relationship Fall 2022
G2 Badge: Security Users Most Likely to Recommend Fall 2022
G2 Badge: Email Gateway Best Relationship Fall 2022
G2 Badge: Email Gateway Best Meets Requirements Fall 2022
G2 Badge - Users Most Likely to Recommend Summer 2022
G2 Badge: Email Gateway Best Results Fall 2022
G2 Badge: Email Gateway Best Usability Fall 2022
G2 Badge: Email Gateway Best Support Fall 2022
G2 Badge: Email Gateway Easiest To Use Fall 2022
G2 Badge: Email Gateway Easiest Setup Fall 2022
G2 Badge: Email Gateway Easiest Admin Fall 2022
G2 Badge: Email Gateway Easiest to do Business with Fall 2022
G2 Badge: Email Gateway Highest User Adoption 2022
G2 Badge: Email Gateway High Performer Fall 2022
G2 Badge: Email Gateway Momentum Leader Fall 2022
G2 Badge: Email Gateway Most Implementable Fall 2022
G2 Badge: Email Gateway Users Most Likely to Recommend Fall 2022