Connecticut AG Enforces HIPAA Privacy Rules Against Hospital and its Business Associate

Snell & Wilmer
Contact

Last week, the Connecticut Attorney General’s office announced that it had entered into a settlement agreement with the Hartford Hospital and its business associate vendor, the EMC Corporation (EMC), to resolve claims arising from an investigation into the 2012 theft of a laptop containing unencrypted patient information.  The hospital and business associate agreed to (1) collectively pay $90,000 to resolve the state-based HIPAA claims and (2) implement or continue new training requirements and other policies in response to the breach.

This case is a good reminder that Section 13410(e) of the HITECH Act gave State Attorneys General the authority to bring civil actions on behalf of state residents for violations of HIPAA.  The HITECH Act permits State Attorneys General to obtain damages on behalf of state residents or to enjoin further violations of the HIPAA Privacy and Security Rules.

This case also seems especially noteworthy in light of the recent U.S. Department of Health and Human Services (HHS) Office of  the Inspector General’s comments about the relative dearth of HIPAA enforcement activity by the federal HHS Office of Civil Rights, as noted in our recent blog post.  As such, this Connecticut AG enforcement action could represent the beginning of a new wave of HIPAA enforcement activity instituted by states Attorneys Generals.

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Snell & Wilmer | Attorney Advertising

Written by:

Snell & Wilmer
Contact
more
less

Snell & Wilmer on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide