In its first enforcement action against a state agency, the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) settled last month with Alaska’s Department of Health and Social Services (DHSS) for HIPAA security violations it reported as required by HITECH. DHSS entered into a settlement agreement and agreed to pay $1,700,000 after a USB hard drive (an electronic storage device) potentially containing electronic protected health information (ePHI) was stolen from the vehicle of a DHSS computer technician in October 2009.
The HITECH Breach Notification Rule requires covered entities to report a breach, an impermissible use or disclosure of ePHI, of 500 individuals or more to the Secretary of HHS and the media. Smaller breaches affecting less than 500 individuals must be reported to the Secretary of HHS annually. OCR investigates each breach of 500 individuals or more reported under HITECH. In this case, OCR reviewed DHSS’s written response, policies, procedures, information regarding training activities and documentation related to compliance with the Privacy and Security Rules, and conducted on-site interviews of the DHSS workforce. At the conclusion of its investigation, OCR found that DHSS did not...
Please see full alert below for more information.
Firefox recommends the PDF Plugin for Mac OS X for viewing PDF documents in your browser.
We can also show you Legal Updates using the Google Viewer; however, you will need to be logged into Google Docs to view them.
Please choose one of the above to proceed!
LOADING PDF: If there are any problems, click here to download the file.