Data Breach, HIPAA / HITECH Enforcement, News Events, OCR HIPAA Audits, Risk Analysis/Risk Management

Dermatology Practice Settles Potential HIPAA Violations $150,000 Plus Corrective Action Plan

Adult & Pediatric Dermatology, P.C., of Concord, Mass., (APDerm) has agreed to settle potential violations of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy,  Security, and Breach Notification Rules with the Department of Health and Human Services, agreeing to a $150,000 payment. APDerm will also be required to implement a corrective action plan to correct deficiencies in its HIPAA compliance program.  APDerm is a private practice that delivers dermatology services in four locations in Massachusetts and two in New Hampshire. This case marks the first settlement with a covered entity for not having policies and procedures in place to address the breach notification provisions of the Health Information Technology for Economic and Clinical Health (HITECH) Act, passed as part of American Recovery and Reinvestment Act of 2009 (ARRA).

The HHS Office for Civil Rights (OCR) opened an investigation of APDerm upon receiving a report that an unencrypted thumb drive containing the electronic protected health information (ePHI) of approximately 2,200 individuals was stolen from a vehicle of one its staff members. The thumb drive was never recovered.  The investigation revealed that APDerm had not conducted an accurate and thorough analysis of the potential risks and vulnerabilities to the confidentiality of ePHI as part of its security management process.  Further, APDerm did not fully comply with requirements of the Breach Notification Rule to have in place written policies and procedures and train workforce members.

In addition to a $150,000 resolution amount, the settlement includes a corrective action plan requiring AP Derm to develop a risk analysis and risk management plan to address and mitigate any security risks and vulnerabilities, as well as to provide an implementation report to OCR.

The resolution agreement and press release can be found on the OCR website at http://www.hhs.gov/ocr/privacy/hipaa/enforcement/examples/apderm-agreement.html.

For assistance please contact RISC Management.

 

Data Breach, Education, HIPAA / HITECH Enforcement, Meaningful Use, News Events, OCR HIPAA Audits, Tip of the Week, Upcoming Events

Gazzang and RISC Management Announce Upcoming Webinar to Help Companies Minimize Risk of Sensitive Data Exposure

The HIPAA Omnibus Rule enhances requirements and penalties for covered entities and business associates alike. As organizations rush to comply with the new rules, many are turning to Gazzang, the big data security experts, for help securing protected health information (PHI) and partner RISC Management to assess, document, and achieve compliance.

Join Chris Heuman- Practice Leader of RISC Management & Consulting along with David Tishgart-Senior Director of Marketing at Gazzang as they present information to understand what constitutes a breach and how best to protect regulated data such as electronic Protected Health Information (ePHI). Discover the best route for navigating the breach risk assessment requirements and minimize your chances of having to report a breach!

Chris Heuman
Chris Heuman
David Tishgart
David Tishgart

Gazzang zNcrypt™ for Health Care can be applied easily, quickly, and economically as a solution for data privacy and security requirements defined within HIPAA and HITECH. Through AES-256 encryption, advanced key management, and process-based access controls, zNcrypt provides transparent data encryption for any database or application running on Linux, including big data environments. Additionally, Gazzang zTrustee™ protects the Gazzang encryption keys with several layers of advanced techniques to ensure the key is only accessible by authorized parties. In the event of a data breach, encryption can help organizations protect sensitive PHI and may enable them to claim “Safe Harbor.”

“Data breaches such as the one experienced by Advocate Health Group affecting more than four million patients, and the subsequent huge class action lawsuit need not occur. A thorough risk analysis, as required by HIPAA, and implementation of stable, supportable encryption technology could have saved the organization a great deal of cost and time, and more than four million patients a lot of stress.” said Chris Heuman, Practice Leader at RISC Management.

Gazzang and RISC Management are hosting a webinar titled, “Are You Ready for the Final HIPAA Omnibus Rule Changes?” on Wednesday, November 6 at 12:00 p.m. ET. Click here to register and learn what constitutes a breach and how best to protect regulated data such as ePHI.

 About RISC Management

RISC Management is an organization dedicated to data privacy and information security, focused primarily on healthcare, banking and finance, and higher education. RISC helps to protect the regulated and sensitive data of our clients and their customers. RISC provides a wide array of compliance and security services to help ensure our clients understand legal and industry requirements. Our experts identify, analyze, document, and remediate risks and vulnerabilities to protect sensitive information. For more information visit www.RISCsecurity.com .

Media Contact

RISC Management
Rose Rienton, MSN, RN

Rose.Rienton@RISCsecurity.com

 About Gazzang

Gazzang provides data security solutions and expertise to help enterprises protect sensitive information and maintain performance in big data and cloud environments. Our technology enables SaaS vendors, health care organizations, financial institutions, public sector agencies and more to meet regulatory compliance initiatives, secure personally identifiable information and prevent unauthorized access to sensitive data and systems. The company is headquartered in Austin, Texas and backed by Austin Ventures and Silver Creek Ventures. For more information, visit www.gazzang.com.

Media Contact

Gazzang
Cybele Diamandopoulos

(512) 535-4422

cybele@foliocom.com