Fresenius Pays OCR $3.5M for Five Separate Data Breaches Affecting a Total of 521 Individuals

Robinson+Cole Data Privacy + Security Insider
Contact

In the first settlement for HIPAA violations in 2018, Fresenius Medical Care North America (Fresenius) has agreed to pay $3.5 million to the Office for Civil Rights (OCR) to settle allegations against it relating to five data breaches that occurred over a four month period in 2012. Interestingly, the five separate breaches affected the information of 521 individuals, making some question whether the punishment fits the crime.

The data breaches occurred when two desktop computers were stolen during a break-in into one of its facilities; the theft of an unencrypted USB drive; a lost hard drive; a stolen laptop out of an employee’s car; and three desktop computers and an encrypted laptop were stolen out of another of its facilities.

According to the OCR, its investigation into the incidents established that Fresenius failed to conduct a comprehensive and accurate risk analysis to identify risks to ePHI, that it failed to implement policies and procedures regarding the receipt and removal of computer hardware and storage devices from its facilities, that it failed to implement encryption technology,  failed to properly safeguard the physical facilities which led to the theft of desktop computers, and failed to have policies and procedures to address security breaches.

In addition to paying the hefty fine, Fresenius agreed to implement a corrective action plan, including adopting policies and procedures, conduct a comprehensive risk analysis and implement a risk management plan.

[View source.]

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Robinson+Cole Data Privacy + Security Insider | Attorney Advertising

Written by:

Robinson+Cole Data Privacy + Security Insider
Contact
more
less

Robinson+Cole Data Privacy + Security Insider on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide