SlideShare a Scribd company logo
FISHERBROYLES.COM
TH E NE X T GE NE R A T I O N LA W FI R M ®
Failure to Execute a HIPAA Business Associate Agreement
Results in $1.55 Million Settlement
PRACTICE AREA / INDUSTRY: HEALTHCARE; WHITE COLLAR LITIGATION &
GOVERNEMENT INVESTIGATIONS
Brian E. Dickerson Anthony J. Calamunci
brian.dickerson@fisherbroyles.com anthony.calamunci@fisherbroyles.com
202.570.0248 419.376.1776
Nicole Hughes Waid
nicole.waid@fisherbroyles.com
202.906.9572
March 17, 2016
Yesterday the U.S. Department of Health & Human Services (“HHS”) Office for Civil Rights (“OCR”)
announced that North Memorial Health System of Minnesota (“North Memorial”) agreed to pay $1.5 million to
settle charges that it potentially violated HIPAA Privacy and Security Rules by improperly disclosing PHI on
nearly 300,000 patients during a five month period in 2011.
North Memorial reported on September 27, 2011, that an unencrypted laptop that contained electronic PHI of
6,697 patients was stolen on July 25, 2011, from an employee’s locked vehicle. North Memorial disclosed
additional violations during the course of the OCR investigation. Specifically, North Memorial disclosed that
the company did not have a written business associate agreement (“BAA”) with its third party billing company,
Accretive, from March 21, 2011 to October 14, 2011 when a written BAA was provided, resulting in the
improper disclosure of PHI of at least 289,904 individuals.
HIPAA Privacy and Security Rules mandate that organizations must have in place a BAA with any company
that has access to PHI, both non-electronic and electronic. OCR’s investigation indicated that North Memorial
gave Accretive access to its hospital database and also access to non-electronic PHI when services were
performed on-site.
FISHERBROYLES.COM
TH E NE X T GE NE R A T I O N LA W FI R M ®
HIPAA Privacy and Security Rules require a thorough and complete risk analysis to identify potential
vulnerabilities and address potential risks. OCR determined that North Memorial failed to complete a risk
analysis that addressed vulnerabilities and risks to electronic PHI across its entire IT infrastructure that
included all applications, software, databases, servers, workstations, mobile devices and electronic media,
network administration and security devices, and associated business processes, such as those that allowed
an employee to have an unencrypted laptop off-site.
“Two major cornerstones of the HIPAA Rules were overlooked by this entity,” said Jocelyn Samuels, Director of
the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). “Organizations must have
in place compliant business associate agreements as well as an accurate and thorough risk analysis that
addresses their enterprise-wide IT infrastructure.”
In addition to the $1,550,000 payment, under the resolution agreement, North Memorial is required to develop a
robust, organization-wide risk analysis and risk management plan. North Memorial has agreed to complete this
plan within 180 days and will include an inventory of all equipment that stores PHI. North Memorial will also train
appropriate workforce members on all policies and procedures newly developed or revised pursuant to this
corrective action plan. Please click here to view the Resolution Agreement and Corrective Action Plan.
This settlement illustrates OCR’s heightened scrutiny of business associate agreements and third-party vendor
relationships. Last year OCR reached a $3.5 million settlement with Triple-S Management Corp for HIPAA
violations that included not having BAAs with vendors. A company’s PHI safeguards are only as strong as the
safeguards of the vendors with whom the company does business. Covered entities must exercise due diligence
in the selection of third-party vendors, review the vendor’s cyber security and data breach plans, ensure that BAAs
are in place and are being followed, review contractual obligations, and require audits of PHI safeguards. Failure
to do so not only places personal health information at risk, but can also be very costly for companies who are
found to be in breach of their duties.
For further information on the subject matter of this alert, please contact the following FisherBroyles attorneys:
Brian E. Dickerson
brian.dickerson@fisherbroyles.com
202.570.0248
Nicole Hughes Waid
nicole.waid@fisherbroyles.com
202.906.9572
Anthony J. Calamunci
anthony.calamunci@fisherbroyles.com
419.376.1776

More Related Content

What's hot

Role-Based Access Governance and HIPAA Compliance: A Pragmatic Approach
Role-Based Access Governance and HIPAA Compliance: A Pragmatic ApproachRole-Based Access Governance and HIPAA Compliance: A Pragmatic Approach
Role-Based Access Governance and HIPAA Compliance: A Pragmatic Approach
EMC
 
HIPAA Security Risk Analysis for Business Associates
HIPAA Security Risk Analysis for Business AssociatesHIPAA Security Risk Analysis for Business Associates
HIPAA Security Risk Analysis for Business Associates
Redspin, Inc.
 
Redspin PHI Breach Report 2012
Redspin PHI Breach Report 2012Redspin PHI Breach Report 2012
Redspin PHI Breach Report 2012Redspin, Inc.
 
Implications of hipaa non compliance
Implications of hipaa non complianceImplications of hipaa non compliance
Implications of hipaa non compliance
Aegify Inc.
 
US Data Privacy Laws
US Data Privacy LawsUS Data Privacy Laws
US Data Privacy LawsIDG Connect
 
Law_Firm_Info_Security_Report_June2011 (1)
Law_Firm_Info_Security_Report_June2011 (1)Law_Firm_Info_Security_Report_June2011 (1)
Law_Firm_Info_Security_Report_June2011 (1)Aspiration Software LLC
 
The real reason why physicians must comply with HIPAA. What the government do...
The real reason why physicians must comply with HIPAA. What the government do...The real reason why physicians must comply with HIPAA. What the government do...
The real reason why physicians must comply with HIPAA. What the government do...
CureMD
 
Ftc As Enforcer Proposed Data Breach Notification Rule For Personal Health R...
Ftc As Enforcer  Proposed Data Breach Notification Rule For Personal Health R...Ftc As Enforcer  Proposed Data Breach Notification Rule For Personal Health R...
Ftc As Enforcer Proposed Data Breach Notification Rule For Personal Health R...Davis Wright Tremaine LLP
 
Mha 690 presentation hippa
Mha 690 presentation hippaMha 690 presentation hippa
Mha 690 presentation hippa
belle0508
 
Cost of Data Breah in Healthcare_Quinlan, Courtney
Cost of Data Breah in Healthcare_Quinlan, CourtneyCost of Data Breah in Healthcare_Quinlan, Courtney
Cost of Data Breah in Healthcare_Quinlan, Courtneycourtneyquinlan
 
Cybercrime and the Healthcare Industry
Cybercrime and the Healthcare IndustryCybercrime and the Healthcare Industry
Cybercrime and the Healthcare Industry
EMC
 
HIPAA Final Omnibus Rule Playbook
HIPAA Final Omnibus Rule PlaybookHIPAA Final Omnibus Rule Playbook
HIPAA Final Omnibus Rule Playbook
Elizabeth Dimit
 
Privacy Do's and Don'ts for Customer Service Representatives
Privacy Do's and Don'ts for Customer Service RepresentativesPrivacy Do's and Don'ts for Customer Service Representatives
Privacy Do's and Don'ts for Customer Service Representatives
Art Hall
 
MBM Achieving HIPAA Compliance Whitepaper
MBM Achieving HIPAA Compliance WhitepaperMBM Achieving HIPAA Compliance Whitepaper
MBM Achieving HIPAA Compliance WhitepaperMBMeHealthCareSolutions
 
Health Care Fraud Hurts!
Health Care Fraud Hurts!Health Care Fraud Hurts!
Health Care Fraud Hurts!
urlstevens
 
HIPAA Privacy, Security, Breach Overview
HIPAA Privacy, Security, Breach OverviewHIPAA Privacy, Security, Breach Overview
HIPAA Privacy, Security, Breach Overview
HealthCare Too, LLC
 
MichBIO_-_HIPAA__Industry-Provider_Interactions__and_Related_Compliance_Matte...
MichBIO_-_HIPAA__Industry-Provider_Interactions__and_Related_Compliance_Matte...MichBIO_-_HIPAA__Industry-Provider_Interactions__and_Related_Compliance_Matte...
MichBIO_-_HIPAA__Industry-Provider_Interactions__and_Related_Compliance_Matte...Colin Zick
 
The New HIPAA Privacy Rule
The New HIPAA Privacy RuleThe New HIPAA Privacy Rule
The New HIPAA Privacy Rule
Michael Witt
 

What's hot (19)

Role-Based Access Governance and HIPAA Compliance: A Pragmatic Approach
Role-Based Access Governance and HIPAA Compliance: A Pragmatic ApproachRole-Based Access Governance and HIPAA Compliance: A Pragmatic Approach
Role-Based Access Governance and HIPAA Compliance: A Pragmatic Approach
 
HIPAA Security Risk Analysis for Business Associates
HIPAA Security Risk Analysis for Business AssociatesHIPAA Security Risk Analysis for Business Associates
HIPAA Security Risk Analysis for Business Associates
 
Redspin PHI Breach Report 2012
Redspin PHI Breach Report 2012Redspin PHI Breach Report 2012
Redspin PHI Breach Report 2012
 
Implications of hipaa non compliance
Implications of hipaa non complianceImplications of hipaa non compliance
Implications of hipaa non compliance
 
US Data Privacy Laws
US Data Privacy LawsUS Data Privacy Laws
US Data Privacy Laws
 
Law_Firm_Info_Security_Report_June2011 (1)
Law_Firm_Info_Security_Report_June2011 (1)Law_Firm_Info_Security_Report_June2011 (1)
Law_Firm_Info_Security_Report_June2011 (1)
 
HITECH-Changes-to-HIPAA
HITECH-Changes-to-HIPAAHITECH-Changes-to-HIPAA
HITECH-Changes-to-HIPAA
 
The real reason why physicians must comply with HIPAA. What the government do...
The real reason why physicians must comply with HIPAA. What the government do...The real reason why physicians must comply with HIPAA. What the government do...
The real reason why physicians must comply with HIPAA. What the government do...
 
Ftc As Enforcer Proposed Data Breach Notification Rule For Personal Health R...
Ftc As Enforcer  Proposed Data Breach Notification Rule For Personal Health R...Ftc As Enforcer  Proposed Data Breach Notification Rule For Personal Health R...
Ftc As Enforcer Proposed Data Breach Notification Rule For Personal Health R...
 
Mha 690 presentation hippa
Mha 690 presentation hippaMha 690 presentation hippa
Mha 690 presentation hippa
 
Cost of Data Breah in Healthcare_Quinlan, Courtney
Cost of Data Breah in Healthcare_Quinlan, CourtneyCost of Data Breah in Healthcare_Quinlan, Courtney
Cost of Data Breah in Healthcare_Quinlan, Courtney
 
Cybercrime and the Healthcare Industry
Cybercrime and the Healthcare IndustryCybercrime and the Healthcare Industry
Cybercrime and the Healthcare Industry
 
HIPAA Final Omnibus Rule Playbook
HIPAA Final Omnibus Rule PlaybookHIPAA Final Omnibus Rule Playbook
HIPAA Final Omnibus Rule Playbook
 
Privacy Do's and Don'ts for Customer Service Representatives
Privacy Do's and Don'ts for Customer Service RepresentativesPrivacy Do's and Don'ts for Customer Service Representatives
Privacy Do's and Don'ts for Customer Service Representatives
 
MBM Achieving HIPAA Compliance Whitepaper
MBM Achieving HIPAA Compliance WhitepaperMBM Achieving HIPAA Compliance Whitepaper
MBM Achieving HIPAA Compliance Whitepaper
 
Health Care Fraud Hurts!
Health Care Fraud Hurts!Health Care Fraud Hurts!
Health Care Fraud Hurts!
 
HIPAA Privacy, Security, Breach Overview
HIPAA Privacy, Security, Breach OverviewHIPAA Privacy, Security, Breach Overview
HIPAA Privacy, Security, Breach Overview
 
MichBIO_-_HIPAA__Industry-Provider_Interactions__and_Related_Compliance_Matte...
MichBIO_-_HIPAA__Industry-Provider_Interactions__and_Related_Compliance_Matte...MichBIO_-_HIPAA__Industry-Provider_Interactions__and_Related_Compliance_Matte...
MichBIO_-_HIPAA__Industry-Provider_Interactions__and_Related_Compliance_Matte...
 
The New HIPAA Privacy Rule
The New HIPAA Privacy RuleThe New HIPAA Privacy Rule
The New HIPAA Privacy Rule
 

Viewers also liked

4 communicatiemix
4 communicatiemix4 communicatiemix
4 communicatiemix
Tim Guily
 
Tabla evaluación de recursos web 2jun15
Tabla evaluación de recursos web 2jun15Tabla evaluación de recursos web 2jun15
Tabla evaluación de recursos web 2jun15
Adriana Cadavid
 
Soft skills essentials for software craftsmen
Soft skills essentials for software craftsmenSoft skills essentials for software craftsmen
Soft skills essentials for software craftsmen
Pierluigi Pugliese
 
Social Media Tips
Social Media TipsSocial Media Tips
Social Media Tips
Michael Pingree
 
Zah German Biomass Lca
Zah German Biomass LcaZah German Biomass Lca
Zah German Biomass Lcaguest70aac4
 
Natural Resource Optimization for International Renewable Transition by 2040
Natural Resource Optimization for International Renewable Transition by 2040Natural Resource Optimization for International Renewable Transition by 2040
Natural Resource Optimization for International Renewable Transition by 2040
Naomi Arnold
 
Unidadiii 140712212722-phpapp02
Unidadiii 140712212722-phpapp02Unidadiii 140712212722-phpapp02
Unidadiii 140712212722-phpapp02
Viviana Otero Castañeda
 
NUEVAS TECNOLOGIAS
NUEVAS TECNOLOGIASNUEVAS TECNOLOGIAS
NUEVAS TECNOLOGIAS
CARLOS GAMEZ ORTEGA
 
Chesapeake Colonization
Chesapeake ColonizationChesapeake Colonization
Chesapeake Colonizationwoworks
 
Glosarios 5
Glosarios 5Glosarios 5
Glosarios 5
efren19
 
Textos no literarios
Textos no literarios Textos no literarios
Textos no literarios
Isidora Isidora
 
El estado argentino en la Constitución
El estado argentino en la ConstituciónEl estado argentino en la Constitución
El estado argentino en la Constitución
Marta Cazayous
 
Ландшафтын график 1-р бүлэг
Ландшафтын график 1-р бүлэгЛандшафтын график 1-р бүлэг
Ландшафтын график 1-р бүлэг
Otgonsaikhan Byambasuren
 

Viewers also liked (17)

4 communicatiemix
4 communicatiemix4 communicatiemix
4 communicatiemix
 
Hicheeliin tolovlogoo
Hicheeliin tolovlogooHicheeliin tolovlogoo
Hicheeliin tolovlogoo
 
Tabla evaluación de recursos web 2jun15
Tabla evaluación de recursos web 2jun15Tabla evaluación de recursos web 2jun15
Tabla evaluación de recursos web 2jun15
 
Soft skills essentials for software craftsmen
Soft skills essentials for software craftsmenSoft skills essentials for software craftsmen
Soft skills essentials for software craftsmen
 
Social Media Tips
Social Media TipsSocial Media Tips
Social Media Tips
 
Zah German Biomass Lca
Zah German Biomass LcaZah German Biomass Lca
Zah German Biomass Lca
 
Natural Resource Optimization for International Renewable Transition by 2040
Natural Resource Optimization for International Renewable Transition by 2040Natural Resource Optimization for International Renewable Transition by 2040
Natural Resource Optimization for International Renewable Transition by 2040
 
Unidadiii 140712212722-phpapp02
Unidadiii 140712212722-phpapp02Unidadiii 140712212722-phpapp02
Unidadiii 140712212722-phpapp02
 
NUEVAS TECNOLOGIAS
NUEVAS TECNOLOGIASNUEVAS TECNOLOGIAS
NUEVAS TECNOLOGIAS
 
Chesapeake Colonization
Chesapeake ColonizationChesapeake Colonization
Chesapeake Colonization
 
Lekts 7
Lekts 7Lekts 7
Lekts 7
 
Glosarios 5
Glosarios 5Glosarios 5
Glosarios 5
 
Textos no literarios
Textos no literarios Textos no literarios
Textos no literarios
 
Lekts 2
Lekts 2Lekts 2
Lekts 2
 
Lekts 5
Lekts 5Lekts 5
Lekts 5
 
El estado argentino en la Constitución
El estado argentino en la ConstituciónEl estado argentino en la Constitución
El estado argentino en la Constitución
 
Ландшафтын график 1-р бүлэг
Ландшафтын график 1-р бүлэгЛандшафтын график 1-р бүлэг
Ландшафтын график 1-р бүлэг
 

Similar to Failure to Execute a HIPAA Business Associate Agreement Results in $1.55 Million Settlement

Sarah Kim HIPAA for Small Providers
Sarah Kim HIPAA for Small ProvidersSarah Kim HIPAA for Small Providers
Sarah Kim HIPAA for Small ProvidersSarah Kim
 
Hipaa for business associates simple
Hipaa for business associates   simpleHipaa for business associates   simple
Hipaa for business associates simple
Jose Ivan Delgado, Ph.D.
 
HIPAA Part I the Law Test
HIPAA Part I  the Law TestHIPAA Part I  the Law Test
HIPAA Part I the Law Test
Sachiko Hurst
 
The Startup Path to HIPAA Compliance
The Startup Path to HIPAA ComplianceThe Startup Path to HIPAA Compliance
The Startup Path to HIPAA Compliance
Jim Anfield
 
HIPAA Panel Discussion
HIPAA Panel Discussion HIPAA Panel Discussion
HIPAA Panel Discussion
Dan Wellisch
 
Meeting the Challenges of HIPAA Compliance, Phishing Attacks, and Mobile Secu...
Meeting the Challenges of HIPAA Compliance, Phishing Attacks, and Mobile Secu...Meeting the Challenges of HIPAA Compliance, Phishing Attacks, and Mobile Secu...
Meeting the Challenges of HIPAA Compliance, Phishing Attacks, and Mobile Secu...
Envision Technology Advisors
 
WhitePaper- Archiving Supports HIPAA Compliance
WhitePaper- Archiving Supports HIPAA ComplianceWhitePaper- Archiving Supports HIPAA Compliance
WhitePaper- Archiving Supports HIPAA Compliance
Succor Consulting Group, Inc.
 
Hitech changes-to-hipaa
Hitech changes-to-hipaaHitech changes-to-hipaa
Hitech changes-to-hipaageeksikh
 
HIPAA and Privacy for Researchers
HIPAA and Privacy for ResearchersHIPAA and Privacy for Researchers
HIPAA and Privacy for Researchers
Jason Karn
 
HIPAA/HITECH Requirements for FQHCs and the New Omnibus Rule
HIPAA/HITECH Requirements for FQHCs and the New Omnibus RuleHIPAA/HITECH Requirements for FQHCs and the New Omnibus Rule
HIPAA/HITECH Requirements for FQHCs and the New Omnibus Rule
Michigan Primary Care Association
 
Economic Stimulus Package V4
Economic Stimulus Package V4Economic Stimulus Package V4
Economic Stimulus Package V4
bakerdb
 
Health care compliance webinar may 10 2017
Health care compliance webinar may 10 2017Health care compliance webinar may 10 2017
Health care compliance webinar may 10 2017
Kimberly Simon MBA
 
Protecting Patient Health Information in the HITECH Era
Protecting Patient Health Information in the HITECH EraProtecting Patient Health Information in the HITECH Era
Protecting Patient Health Information in the HITECH Era
Rapid7
 
Chapter 14 Managing Projects 569 A Shaky Start for Healthcare.Gov CAS.pdf
Chapter 14 Managing Projects 569 A Shaky Start for Healthcare.Gov CAS.pdfChapter 14 Managing Projects 569 A Shaky Start for Healthcare.Gov CAS.pdf
Chapter 14 Managing Projects 569 A Shaky Start for Healthcare.Gov CAS.pdf
prajeetjain
 
HIPAA and HITECH : What you need to know
HIPAA and HITECH : What you need to knowHIPAA and HITECH : What you need to know
HIPAA and HITECH : What you need to know
Shred-it
 
MPCA HIPAA Compliance/Meaningful Use Requirements and Security Risk Assessmen...
MPCA HIPAA Compliance/Meaningful Use Requirements and Security Risk Assessmen...MPCA HIPAA Compliance/Meaningful Use Requirements and Security Risk Assessmen...
MPCA HIPAA Compliance/Meaningful Use Requirements and Security Risk Assessmen...
Michigan Primary Care Association
 
HealthCare Compliance - HIPAA and HITRUST
HealthCare Compliance - HIPAA and HITRUSTHealthCare Compliance - HIPAA and HITRUST
HealthCare Compliance - HIPAA and HITRUST
Kimberly Simon MBA
 
Hipaa omnibus
Hipaa omnibusHipaa omnibus
Hipaa omnibus
wardell henley
 
Hi paa and eh rs
Hi paa and eh rsHi paa and eh rs
Hi paa and eh rssupportc2go
 
Chapter 10 Privacy and Security of Health RecordsLearnin.docx
Chapter 10 Privacy and Security of Health RecordsLearnin.docxChapter 10 Privacy and Security of Health RecordsLearnin.docx
Chapter 10 Privacy and Security of Health RecordsLearnin.docx
cravennichole326
 

Similar to Failure to Execute a HIPAA Business Associate Agreement Results in $1.55 Million Settlement (20)

Sarah Kim HIPAA for Small Providers
Sarah Kim HIPAA for Small ProvidersSarah Kim HIPAA for Small Providers
Sarah Kim HIPAA for Small Providers
 
Hipaa for business associates simple
Hipaa for business associates   simpleHipaa for business associates   simple
Hipaa for business associates simple
 
HIPAA Part I the Law Test
HIPAA Part I  the Law TestHIPAA Part I  the Law Test
HIPAA Part I the Law Test
 
The Startup Path to HIPAA Compliance
The Startup Path to HIPAA ComplianceThe Startup Path to HIPAA Compliance
The Startup Path to HIPAA Compliance
 
HIPAA Panel Discussion
HIPAA Panel Discussion HIPAA Panel Discussion
HIPAA Panel Discussion
 
Meeting the Challenges of HIPAA Compliance, Phishing Attacks, and Mobile Secu...
Meeting the Challenges of HIPAA Compliance, Phishing Attacks, and Mobile Secu...Meeting the Challenges of HIPAA Compliance, Phishing Attacks, and Mobile Secu...
Meeting the Challenges of HIPAA Compliance, Phishing Attacks, and Mobile Secu...
 
WhitePaper- Archiving Supports HIPAA Compliance
WhitePaper- Archiving Supports HIPAA ComplianceWhitePaper- Archiving Supports HIPAA Compliance
WhitePaper- Archiving Supports HIPAA Compliance
 
Hitech changes-to-hipaa
Hitech changes-to-hipaaHitech changes-to-hipaa
Hitech changes-to-hipaa
 
HIPAA and Privacy for Researchers
HIPAA and Privacy for ResearchersHIPAA and Privacy for Researchers
HIPAA and Privacy for Researchers
 
HIPAA/HITECH Requirements for FQHCs and the New Omnibus Rule
HIPAA/HITECH Requirements for FQHCs and the New Omnibus RuleHIPAA/HITECH Requirements for FQHCs and the New Omnibus Rule
HIPAA/HITECH Requirements for FQHCs and the New Omnibus Rule
 
Economic Stimulus Package V4
Economic Stimulus Package V4Economic Stimulus Package V4
Economic Stimulus Package V4
 
Health care compliance webinar may 10 2017
Health care compliance webinar may 10 2017Health care compliance webinar may 10 2017
Health care compliance webinar may 10 2017
 
Protecting Patient Health Information in the HITECH Era
Protecting Patient Health Information in the HITECH EraProtecting Patient Health Information in the HITECH Era
Protecting Patient Health Information in the HITECH Era
 
Chapter 14 Managing Projects 569 A Shaky Start for Healthcare.Gov CAS.pdf
Chapter 14 Managing Projects 569 A Shaky Start for Healthcare.Gov CAS.pdfChapter 14 Managing Projects 569 A Shaky Start for Healthcare.Gov CAS.pdf
Chapter 14 Managing Projects 569 A Shaky Start for Healthcare.Gov CAS.pdf
 
HIPAA and HITECH : What you need to know
HIPAA and HITECH : What you need to knowHIPAA and HITECH : What you need to know
HIPAA and HITECH : What you need to know
 
MPCA HIPAA Compliance/Meaningful Use Requirements and Security Risk Assessmen...
MPCA HIPAA Compliance/Meaningful Use Requirements and Security Risk Assessmen...MPCA HIPAA Compliance/Meaningful Use Requirements and Security Risk Assessmen...
MPCA HIPAA Compliance/Meaningful Use Requirements and Security Risk Assessmen...
 
HealthCare Compliance - HIPAA and HITRUST
HealthCare Compliance - HIPAA and HITRUSTHealthCare Compliance - HIPAA and HITRUST
HealthCare Compliance - HIPAA and HITRUST
 
Hipaa omnibus
Hipaa omnibusHipaa omnibus
Hipaa omnibus
 
Hi paa and eh rs
Hi paa and eh rsHi paa and eh rs
Hi paa and eh rs
 
Chapter 10 Privacy and Security of Health RecordsLearnin.docx
Chapter 10 Privacy and Security of Health RecordsLearnin.docxChapter 10 Privacy and Security of Health RecordsLearnin.docx
Chapter 10 Privacy and Security of Health RecordsLearnin.docx
 

Recently uploaded

VVIP Dehradun Girls 9719300533 Heat-bake { Dehradun } Genteel ℂall Serviℂe By...
VVIP Dehradun Girls 9719300533 Heat-bake { Dehradun } Genteel ℂall Serviℂe By...VVIP Dehradun Girls 9719300533 Heat-bake { Dehradun } Genteel ℂall Serviℂe By...
VVIP Dehradun Girls 9719300533 Heat-bake { Dehradun } Genteel ℂall Serviℂe By...
rajkumar669520
 
Surgery-Mini-OSCE-All-Past-Years-Questions-Modified.
Surgery-Mini-OSCE-All-Past-Years-Questions-Modified.Surgery-Mini-OSCE-All-Past-Years-Questions-Modified.
Surgery-Mini-OSCE-All-Past-Years-Questions-Modified.
preciousstephanie75
 
Deep Leg Vein Thrombosis (DVT): Meaning, Causes, Symptoms, Treatment, and Mor...
Deep Leg Vein Thrombosis (DVT): Meaning, Causes, Symptoms, Treatment, and Mor...Deep Leg Vein Thrombosis (DVT): Meaning, Causes, Symptoms, Treatment, and Mor...
Deep Leg Vein Thrombosis (DVT): Meaning, Causes, Symptoms, Treatment, and Mor...
The Lifesciences Magazine
 
CHAPTER 1 SEMESTER V PREVENTIVE-PEDIATRICS.pdf
CHAPTER 1 SEMESTER V PREVENTIVE-PEDIATRICS.pdfCHAPTER 1 SEMESTER V PREVENTIVE-PEDIATRICS.pdf
CHAPTER 1 SEMESTER V PREVENTIVE-PEDIATRICS.pdf
Sachin Sharma
 
Medical Technology Tackles New Health Care Demand - Research Report - March 2...
Medical Technology Tackles New Health Care Demand - Research Report - March 2...Medical Technology Tackles New Health Care Demand - Research Report - March 2...
Medical Technology Tackles New Health Care Demand - Research Report - March 2...
pchutichetpong
 
Neuro Saphirex Cranial Brochure
Neuro Saphirex Cranial BrochureNeuro Saphirex Cranial Brochure
Neuro Saphirex Cranial Brochure
RXOOM Healthcare Pvt. Ltd. ​
 
CHAPTER 1 SEMESTER V - ROLE OF PEADIATRIC NURSE.pdf
CHAPTER 1 SEMESTER V - ROLE OF PEADIATRIC NURSE.pdfCHAPTER 1 SEMESTER V - ROLE OF PEADIATRIC NURSE.pdf
CHAPTER 1 SEMESTER V - ROLE OF PEADIATRIC NURSE.pdf
Sachin Sharma
 
GURGAON Call Girls ❤8901183002❤ #ℂALL# #gIRLS# In GURGAON ₹,2500 Cash Payment...
GURGAON Call Girls ❤8901183002❤ #ℂALL# #gIRLS# In GURGAON ₹,2500 Cash Payment...GURGAON Call Girls ❤8901183002❤ #ℂALL# #gIRLS# In GURGAON ₹,2500 Cash Payment...
GURGAON Call Girls ❤8901183002❤ #ℂALL# #gIRLS# In GURGAON ₹,2500 Cash Payment...
ranishasharma67
 
Telehealth Psychology Building Trust with Clients.pptx
Telehealth Psychology Building Trust with Clients.pptxTelehealth Psychology Building Trust with Clients.pptx
Telehealth Psychology Building Trust with Clients.pptx
The Harvest Clinic
 
ICH Guidelines for Pharmacovigilance.pdf
ICH Guidelines for Pharmacovigilance.pdfICH Guidelines for Pharmacovigilance.pdf
ICH Guidelines for Pharmacovigilance.pdf
NEHA GUPTA
 
POLYCYSTIC OVARIAN SYNDROME (PCOS)......
POLYCYSTIC OVARIAN SYNDROME (PCOS)......POLYCYSTIC OVARIAN SYNDROME (PCOS)......
POLYCYSTIC OVARIAN SYNDROME (PCOS)......
Ameena Kadar
 
BOWEL ELIMINATION BY ANUSHRI SRIVASTAVA.pptx
BOWEL ELIMINATION BY ANUSHRI SRIVASTAVA.pptxBOWEL ELIMINATION BY ANUSHRI SRIVASTAVA.pptx
BOWEL ELIMINATION BY ANUSHRI SRIVASTAVA.pptx
AnushriSrivastav
 
Global launch of the Healthy Ageing and Prevention Index 2nd wave – alongside...
Global launch of the Healthy Ageing and Prevention Index 2nd wave – alongside...Global launch of the Healthy Ageing and Prevention Index 2nd wave – alongside...
Global launch of the Healthy Ageing and Prevention Index 2nd wave – alongside...
ILC- UK
 
Contact ME {89011**83002} Haridwar ℂall Girls By Full Service Call Girl In Ha...
Contact ME {89011**83002} Haridwar ℂall Girls By Full Service Call Girl In Ha...Contact ME {89011**83002} Haridwar ℂall Girls By Full Service Call Girl In Ha...
Contact ME {89011**83002} Haridwar ℂall Girls By Full Service Call Girl In Ha...
ranishasharma67
 
Artificial Intelligence to Optimize Cardiovascular Therapy
Artificial Intelligence to Optimize Cardiovascular TherapyArtificial Intelligence to Optimize Cardiovascular Therapy
Artificial Intelligence to Optimize Cardiovascular Therapy
Iris Thiele Isip-Tan
 
Navigating Challenges: Mental Health, Legislation, and the Prison System in B...
Navigating Challenges: Mental Health, Legislation, and the Prison System in B...Navigating Challenges: Mental Health, Legislation, and the Prison System in B...
Navigating Challenges: Mental Health, Legislation, and the Prison System in B...
Guillermo Rivera
 
💘Ludhiana ℂall Girls 📞]][89011★83002][[ 📱 ❤ESCORTS service in Ludhiana💃💦Ludhi...
💘Ludhiana ℂall Girls 📞]][89011★83002][[ 📱 ❤ESCORTS service in Ludhiana💃💦Ludhi...💘Ludhiana ℂall Girls 📞]][89011★83002][[ 📱 ❤ESCORTS service in Ludhiana💃💦Ludhi...
💘Ludhiana ℂall Girls 📞]][89011★83002][[ 📱 ❤ESCORTS service in Ludhiana💃💦Ludhi...
ranishasharma67
 
ventilator, child on ventilator, newborn
ventilator, child on ventilator, newbornventilator, child on ventilator, newborn
ventilator, child on ventilator, newborn
Pooja Rani
 
Navigating Women's Health: Understanding Prenatal Care and Beyond
Navigating Women's Health: Understanding Prenatal Care and BeyondNavigating Women's Health: Understanding Prenatal Care and Beyond
Navigating Women's Health: Understanding Prenatal Care and Beyond
Aboud Health Group
 
Dimensions of Healthcare Quality
Dimensions of Healthcare QualityDimensions of Healthcare Quality
Dimensions of Healthcare Quality
Naeemshahzad51
 

Recently uploaded (20)

VVIP Dehradun Girls 9719300533 Heat-bake { Dehradun } Genteel ℂall Serviℂe By...
VVIP Dehradun Girls 9719300533 Heat-bake { Dehradun } Genteel ℂall Serviℂe By...VVIP Dehradun Girls 9719300533 Heat-bake { Dehradun } Genteel ℂall Serviℂe By...
VVIP Dehradun Girls 9719300533 Heat-bake { Dehradun } Genteel ℂall Serviℂe By...
 
Surgery-Mini-OSCE-All-Past-Years-Questions-Modified.
Surgery-Mini-OSCE-All-Past-Years-Questions-Modified.Surgery-Mini-OSCE-All-Past-Years-Questions-Modified.
Surgery-Mini-OSCE-All-Past-Years-Questions-Modified.
 
Deep Leg Vein Thrombosis (DVT): Meaning, Causes, Symptoms, Treatment, and Mor...
Deep Leg Vein Thrombosis (DVT): Meaning, Causes, Symptoms, Treatment, and Mor...Deep Leg Vein Thrombosis (DVT): Meaning, Causes, Symptoms, Treatment, and Mor...
Deep Leg Vein Thrombosis (DVT): Meaning, Causes, Symptoms, Treatment, and Mor...
 
CHAPTER 1 SEMESTER V PREVENTIVE-PEDIATRICS.pdf
CHAPTER 1 SEMESTER V PREVENTIVE-PEDIATRICS.pdfCHAPTER 1 SEMESTER V PREVENTIVE-PEDIATRICS.pdf
CHAPTER 1 SEMESTER V PREVENTIVE-PEDIATRICS.pdf
 
Medical Technology Tackles New Health Care Demand - Research Report - March 2...
Medical Technology Tackles New Health Care Demand - Research Report - March 2...Medical Technology Tackles New Health Care Demand - Research Report - March 2...
Medical Technology Tackles New Health Care Demand - Research Report - March 2...
 
Neuro Saphirex Cranial Brochure
Neuro Saphirex Cranial BrochureNeuro Saphirex Cranial Brochure
Neuro Saphirex Cranial Brochure
 
CHAPTER 1 SEMESTER V - ROLE OF PEADIATRIC NURSE.pdf
CHAPTER 1 SEMESTER V - ROLE OF PEADIATRIC NURSE.pdfCHAPTER 1 SEMESTER V - ROLE OF PEADIATRIC NURSE.pdf
CHAPTER 1 SEMESTER V - ROLE OF PEADIATRIC NURSE.pdf
 
GURGAON Call Girls ❤8901183002❤ #ℂALL# #gIRLS# In GURGAON ₹,2500 Cash Payment...
GURGAON Call Girls ❤8901183002❤ #ℂALL# #gIRLS# In GURGAON ₹,2500 Cash Payment...GURGAON Call Girls ❤8901183002❤ #ℂALL# #gIRLS# In GURGAON ₹,2500 Cash Payment...
GURGAON Call Girls ❤8901183002❤ #ℂALL# #gIRLS# In GURGAON ₹,2500 Cash Payment...
 
Telehealth Psychology Building Trust with Clients.pptx
Telehealth Psychology Building Trust with Clients.pptxTelehealth Psychology Building Trust with Clients.pptx
Telehealth Psychology Building Trust with Clients.pptx
 
ICH Guidelines for Pharmacovigilance.pdf
ICH Guidelines for Pharmacovigilance.pdfICH Guidelines for Pharmacovigilance.pdf
ICH Guidelines for Pharmacovigilance.pdf
 
POLYCYSTIC OVARIAN SYNDROME (PCOS)......
POLYCYSTIC OVARIAN SYNDROME (PCOS)......POLYCYSTIC OVARIAN SYNDROME (PCOS)......
POLYCYSTIC OVARIAN SYNDROME (PCOS)......
 
BOWEL ELIMINATION BY ANUSHRI SRIVASTAVA.pptx
BOWEL ELIMINATION BY ANUSHRI SRIVASTAVA.pptxBOWEL ELIMINATION BY ANUSHRI SRIVASTAVA.pptx
BOWEL ELIMINATION BY ANUSHRI SRIVASTAVA.pptx
 
Global launch of the Healthy Ageing and Prevention Index 2nd wave – alongside...
Global launch of the Healthy Ageing and Prevention Index 2nd wave – alongside...Global launch of the Healthy Ageing and Prevention Index 2nd wave – alongside...
Global launch of the Healthy Ageing and Prevention Index 2nd wave – alongside...
 
Contact ME {89011**83002} Haridwar ℂall Girls By Full Service Call Girl In Ha...
Contact ME {89011**83002} Haridwar ℂall Girls By Full Service Call Girl In Ha...Contact ME {89011**83002} Haridwar ℂall Girls By Full Service Call Girl In Ha...
Contact ME {89011**83002} Haridwar ℂall Girls By Full Service Call Girl In Ha...
 
Artificial Intelligence to Optimize Cardiovascular Therapy
Artificial Intelligence to Optimize Cardiovascular TherapyArtificial Intelligence to Optimize Cardiovascular Therapy
Artificial Intelligence to Optimize Cardiovascular Therapy
 
Navigating Challenges: Mental Health, Legislation, and the Prison System in B...
Navigating Challenges: Mental Health, Legislation, and the Prison System in B...Navigating Challenges: Mental Health, Legislation, and the Prison System in B...
Navigating Challenges: Mental Health, Legislation, and the Prison System in B...
 
💘Ludhiana ℂall Girls 📞]][89011★83002][[ 📱 ❤ESCORTS service in Ludhiana💃💦Ludhi...
💘Ludhiana ℂall Girls 📞]][89011★83002][[ 📱 ❤ESCORTS service in Ludhiana💃💦Ludhi...💘Ludhiana ℂall Girls 📞]][89011★83002][[ 📱 ❤ESCORTS service in Ludhiana💃💦Ludhi...
💘Ludhiana ℂall Girls 📞]][89011★83002][[ 📱 ❤ESCORTS service in Ludhiana💃💦Ludhi...
 
ventilator, child on ventilator, newborn
ventilator, child on ventilator, newbornventilator, child on ventilator, newborn
ventilator, child on ventilator, newborn
 
Navigating Women's Health: Understanding Prenatal Care and Beyond
Navigating Women's Health: Understanding Prenatal Care and BeyondNavigating Women's Health: Understanding Prenatal Care and Beyond
Navigating Women's Health: Understanding Prenatal Care and Beyond
 
Dimensions of Healthcare Quality
Dimensions of Healthcare QualityDimensions of Healthcare Quality
Dimensions of Healthcare Quality
 

Failure to Execute a HIPAA Business Associate Agreement Results in $1.55 Million Settlement

  • 1. FISHERBROYLES.COM TH E NE X T GE NE R A T I O N LA W FI R M ® Failure to Execute a HIPAA Business Associate Agreement Results in $1.55 Million Settlement PRACTICE AREA / INDUSTRY: HEALTHCARE; WHITE COLLAR LITIGATION & GOVERNEMENT INVESTIGATIONS Brian E. Dickerson Anthony J. Calamunci brian.dickerson@fisherbroyles.com anthony.calamunci@fisherbroyles.com 202.570.0248 419.376.1776 Nicole Hughes Waid nicole.waid@fisherbroyles.com 202.906.9572 March 17, 2016 Yesterday the U.S. Department of Health & Human Services (“HHS”) Office for Civil Rights (“OCR”) announced that North Memorial Health System of Minnesota (“North Memorial”) agreed to pay $1.5 million to settle charges that it potentially violated HIPAA Privacy and Security Rules by improperly disclosing PHI on nearly 300,000 patients during a five month period in 2011. North Memorial reported on September 27, 2011, that an unencrypted laptop that contained electronic PHI of 6,697 patients was stolen on July 25, 2011, from an employee’s locked vehicle. North Memorial disclosed additional violations during the course of the OCR investigation. Specifically, North Memorial disclosed that the company did not have a written business associate agreement (“BAA”) with its third party billing company, Accretive, from March 21, 2011 to October 14, 2011 when a written BAA was provided, resulting in the improper disclosure of PHI of at least 289,904 individuals. HIPAA Privacy and Security Rules mandate that organizations must have in place a BAA with any company that has access to PHI, both non-electronic and electronic. OCR’s investigation indicated that North Memorial gave Accretive access to its hospital database and also access to non-electronic PHI when services were performed on-site.
  • 2. FISHERBROYLES.COM TH E NE X T GE NE R A T I O N LA W FI R M ® HIPAA Privacy and Security Rules require a thorough and complete risk analysis to identify potential vulnerabilities and address potential risks. OCR determined that North Memorial failed to complete a risk analysis that addressed vulnerabilities and risks to electronic PHI across its entire IT infrastructure that included all applications, software, databases, servers, workstations, mobile devices and electronic media, network administration and security devices, and associated business processes, such as those that allowed an employee to have an unencrypted laptop off-site. “Two major cornerstones of the HIPAA Rules were overlooked by this entity,” said Jocelyn Samuels, Director of the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). “Organizations must have in place compliant business associate agreements as well as an accurate and thorough risk analysis that addresses their enterprise-wide IT infrastructure.” In addition to the $1,550,000 payment, under the resolution agreement, North Memorial is required to develop a robust, organization-wide risk analysis and risk management plan. North Memorial has agreed to complete this plan within 180 days and will include an inventory of all equipment that stores PHI. North Memorial will also train appropriate workforce members on all policies and procedures newly developed or revised pursuant to this corrective action plan. Please click here to view the Resolution Agreement and Corrective Action Plan. This settlement illustrates OCR’s heightened scrutiny of business associate agreements and third-party vendor relationships. Last year OCR reached a $3.5 million settlement with Triple-S Management Corp for HIPAA violations that included not having BAAs with vendors. A company’s PHI safeguards are only as strong as the safeguards of the vendors with whom the company does business. Covered entities must exercise due diligence in the selection of third-party vendors, review the vendor’s cyber security and data breach plans, ensure that BAAs are in place and are being followed, review contractual obligations, and require audits of PHI safeguards. Failure to do so not only places personal health information at risk, but can also be very costly for companies who are found to be in breach of their duties. For further information on the subject matter of this alert, please contact the following FisherBroyles attorneys: Brian E. Dickerson brian.dickerson@fisherbroyles.com 202.570.0248 Nicole Hughes Waid nicole.waid@fisherbroyles.com 202.906.9572 Anthony J. Calamunci anthony.calamunci@fisherbroyles.com 419.376.1776