The last major settlement of 2019 regarding violations of the Health Insurance Portability and Accountability Act (HIPAA) may not have been the largest penalty of the year; but it nonetheless demonstrates the importance of compliance with HIPAA.
On December 30, 2019, the Office for Civil Rights (OCR) at the U.S. Department of Health and Human Services (HHS) announced its settlement with West Georgia Ambulance, Inc. (West Georgia) for potential violations of HIPAA.
After an unencrypted laptop fell off the back bumper of the companyโs ambulance, West Georgia submitted a breach report with the OCR. The laptop contained the electronic protected health information (ePHI) of 500 individuals. The OCRโs investigation found the company had continuing non-compliance with the HIPAA Privacy and Security Rules because it failed to:
West Georgia agreed to pay $65,000 and adopt a 2-year corrective action plan (CAP) for future potential violations of HIPAA. The CAP includes some of the following remedial measures:
Now more than ever, those subject to HIPAA (Covered Entities (CEs)) must continue to comply with these obligations to avoid costly outcomes. ComplianceDashboard offers tools to help CEs navigate through the strict requirements of HIPAA.
The information and content contained in this blog post are for general informational purposes only, and does not, and is not intended to, constitute legal advice.