HHS Settles HIPAA Security Violations with Healthcare Provider Following Ransomware Attack

Posted by BAS - 25 July, 2024

header-picture

The Department of Health and Human Services (HHS) reached a settlement over potential HIPAA Security Rule violations following a ransomware attack on a healthcare provider operating in Pennsylvania, Ohio, and West Virginia. The provider will pay $950,000 and adhere to a three-year corrective action plan (CAP), monitored by HHS.

The settlement stems from an October 2017 compliance review initiated after media reports of a ransomware incident. HHS found the provider failed to conduct a comprehensive risk analysis, establish emergency response procedures, and implement access control policies for electronic protected health information (ePHI).

The CAP mandates a thorough risk analysis covering all facilities and electronic systems containing ePHI, development of a risk management plan, and periodic reviews of HIPAA policies. Additionally, the provider must submit annual reports to HHS and maintain documentation for six years.

Revised HIPAA policies must address risk management, information system activity review, password management, contingency planning, access control, and business associate agreements. These policies require HHS approval and distribution to all relevant personnel, with annual updates as necessary.

The provider must also revise and implement HIPAA training materials, ensuring all workforce members receive training and certification. Noncompliance events must be promptly investigated and reported to HHS.

HHS highlighted the increasing threat of cyberattacks in healthcare, noting a significant rise in ransomware breaches. The settlement underscores the need for covered entities and business associates to adopt best practices to mitigate cyber risks.


Benefit Allocation Systems (BAS) provides best-in-class, online solutions for: Employee Benefits Enrollment; COBRA; Flexible Spending Accounts (FSAs); Health Reimbursement Accounts (HRAs); Leave of Absence Premium Billing (LOA); Affordable Care Act Record Keeping, Compliance & IRS Reporting (ACA); Group Insurance Premium Billing; Property & Casualty Premium Billing; and Payroll Integration.

MyEnroll360 can Integrate with any insurance carrier for enrollment eligibility management (e.g., Blue Cross, Blue Shield, Aetna, United Health Care, Kaiser, CIGNA and many others), and integrate with any payroll system for enrollment deduction management (e.g., Workday, ADP, Paylocity, PayCor, UKG, and many others).

Topics: HIPAA, MyEnroll360 Security, Technology News, Cybersecurity


Recent Posts

Question of the Week - HRA Reimbursements

read more

Security Tips from the IRS

read more

CCS Commitment to COBRA

read more