Medical Record Snooping Case Leads To A $240K HIPAA Settlement

AC
Ankura Consulting Group LLC
Contributor
Ankura Consulting Group, LLC is an independent global expert services and advisory firm that delivers end-to-end solutions to help clients at critical inflection points related to conflict, crisis, performance, risk, strategy, and transformation. Ankura consists of more than 1,800 professionals and has served 3,000+ clients across 55 countries. Collaborative lateral thinking, hard-earned experience, and multidisciplinary capabilities drive results and Ankura is unrivalled in its ability to assist clients to Protect, Create, and Recover Value. For more information, please visit, ankura.com.
On June 15, 2023, the U.S. Department of Health and Human Services Office for Civil Rights (OCR) announced a settlement for $240,000 with Yakima Valley Memorial Hospital, a not-for-profit community...
United States Food, Drugs, Healthcare, Life Sciences
To print this article, all you need is to be registered or login on Mondaq.com.

On June 15, 2023, the U.S. Department of Health and Human Services Office for Civil Rights (OCR) announced a settlement for $240,000 with Yakima Valley Memorial Hospital, a not-for-profit community hospital located in Yakima, Washington.

In May 2018, OCR launched an investigation into Yakima Valley Memorial Hospital regarding allegations that multiple security guards from the hospital impermissibly accessed around 419 medical records of individuals in violation of the Health Insurance Portability and Accountability Act (HIPAA) regulations. Twenty-three security guards in the hospital used their hospital log-in credentials to access patient medical records maintained through an electronic medical record system without a job-related purpose. The information accessed by the security guards included names, dates of birth, addresses, medical record numbers, notes related to treatment, and information regarding insurance.

As a result of the settlement, Yakima Valley Hospital is required to implement corrective actions and will be monitored by the OCR for two years to ensure the hospital remains in compliance with the HIPAA Security Rule.

Next Steps for Yakima Valley Memorial Hospital:

Yakima Valley Memorial Hospital has agreed to take the following steps for corrective action:

  • Develop and maintain written HIPAA procedures and policies.
  • Enhance existing security training programs to provide information on updated HIPAA procedures and policies.
  • Conduct a thorough risk analysis to determine vulnerabilities and risks to electronic protected health information and implement a risk management plan to mitigate and address identified security risks.

Key Takeaways

  • HIPAA-covered entities must have robust procedures and policies in place to protect patient health information from identity theft and fraud.
  • Internal threats can cause just as much damage as external threats to protected health information.
  • Insider threats can be a result of negligent or careless workers, or the threats can emerge from disgruntled employees.
  • Regardless of the intent of the threat, insider threats are likely to result in data breaches.
  • Prioritize training employees with updated HIPAA procedures and policies.

The resolution agreement and corrective action plan may be found at: https://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/agreements/yakima-ra-cap/index.html

Natasha Ganesh contributed to this article.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

Medical Record Snooping Case Leads To A $240K HIPAA Settlement

United States Food, Drugs, Healthcare, Life Sciences
Contributor
Ankura Consulting Group, LLC is an independent global expert services and advisory firm that delivers end-to-end solutions to help clients at critical inflection points related to conflict, crisis, performance, risk, strategy, and transformation. Ankura consists of more than 1,800 professionals and has served 3,000+ clients across 55 countries. Collaborative lateral thinking, hard-earned experience, and multidisciplinary capabilities drive results and Ankura is unrivalled in its ability to assist clients to Protect, Create, and Recover Value. For more information, please visit, ankura.com.
See More Popular Content From

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More