$1.6 Million HIPAA Penalty for Unsecured Server

Posted by BAS - 19 December, 2019

header-picture

The Texas Health and Human Services Commission received a $1.6 million penalty from the U.S. Department of Health and Human Services for releasing protected health information of 6,617 individuals. The PHI was on a public server for which a flawed software code allowed people to access the server without proper user credentials.

Data disclosed included names addresses, Social Security Numbers, treatments and diagnosis information. The Texas department was not able to determine how many unauthorized people accessed the PHI. The Texas department accepted the penalty and recognized its shortcomings in a lack of controls.

Topics: MyEnroll360 Security


Recent Posts

“Wait—Can Ally Really Answer That?” Surprising (But True) Questions Our AI Can Handle

read more

Question of the Week - Missed COBRA Notice

read more

Fraud Prevention in Benefits Administration: Protecting Plans and Participants

read more