Email this article   Print article 


HIPAA Healthcare Data Breach Fines Climb With Enforcement Boost

By Robert Westervelt
January 08, 2013    1:48 PM ET

Page 2 of 2

Small provider organizations and even larger research facilities often have a hard time addressing and maintaining security and lack adequately trained IT staff and a security officer with the level of authority needed to run an effective program, said Kate Borten, president of The Marblehead Group, a consultancy that specializes in healthcare security. Security hasn't advanced much over the last decade, Borten said. "This is all the tip of the iceberg because we still have organizations that don't understand what the security rules are all about," she said. "We still don't know if organizations are even recognizing and reporting breaches."

Other healthcare organizations have agreed to pay millions of dollars in fines for alleged HIPPA violations in 2012.

In September, the Massachusetts Eye and Ear Associates, Inc. agreed to pay $1.5 million HIPAA fine for the theft of an unencrypted laptop containing about 3,600 of its patients and research subjects, including patient prescriptions and clinical information. The Boston-based firm disclosed the breach, following the HITECH breach notification rules, but investigators found that the firm lacked a security program, failing to adequately implement policies and procedures for the removal of portable devices containing patient data.

Beth Israel Deaconess Medical Center in Boston underwent a similar breach when a laptop was reported stolen in May containing information on 3,900 patients. The hospital is reportedly encrypting more than 1,000 laptops in response to the breach.

In June the Alaska Department of Health and Social Services agreed to pay $1.7 million and said it would implement better security policies and procedures stemming from a 2009 theft of a USB hard drive possibly containing the data on 500 individuals from a computer technician's vehicle.

PUBLISHED JAN. 8, 2013

<< Previous | 1 | 2

To continue reading this article, please download the free CRN Tech News app for your iPad or Windows 8 device.
Related: Videos | Slide Shows | Comments

SHARE THIS ARTICLE

More Security

Recent Articles

10 Security Companies That Have Scored CIA Funding

CIA-funded venture firm invests millions in technology startups, mostly security firms. Find out which security companies won In-Q-Tel funding.

Head-To-Head: Symantec Vs. McAfee In Endpoint Protection

McAfee and Symantec are archrivals with a firm grip on the North American security market. CRN pits both vendors' endpoint security products against each other and names a winner.

The 8 Steps Behind The Massive $45M Cyber Bank Heist

More than $45 million was stolen from banks in the U.S. and 19 other countries in a scheme that law enforcement is calling an international conspiracy to drain millions from bank accounts using stolen debit cards and PIN numbers. Here's how they did it.

  More Slide Shows




Related Videos
Loading...