Dermatology Practice Settles Alleged HIPAA Violations

Rivkin Radler LLP
Contact

Rivkin Radler LLP

On August 23, the U.S. Department of Health and Human Services’ Office for Civil Rights (OCR) announced that Massachusetts-based New England Dermatology, P.C., d/b/a New England Dermatology and Laser Center (NEDLC), agreed to resolve alleged HIPAA violations for a fine of $300,640.

OCR commenced an investigation of NEDLC after the provider filed a breach report stating that empty specimen containers with protected health information (PHI) on the labels were placed in a garbage bin in NEDLC’s parking lot. The labels included patient names and dates of birth, among other things. OCR’s investigation found potential violations of the HIPAA Privacy Rule, including impermissible use and disclosure of PHI as well as a failure to maintain appropriate safeguards to protect the privacy of PHI.

As part of the settlement, NEDLC must also adopt a robust corrective action plan and will be monitored by OCR for two years. Among other things, NEDLC will be required to designate a privacy official who will be responsible for the development and implementation of HIPAA policies and procedures, and to assess, update, and revise its policies and procedures at least annually or as needed.

The settlement reinforces that HIPAA compliance includes not only protection of electronic patient records, but proper handling of physical items as well.

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Rivkin Radler LLP | Attorney Advertising

Written by:

Rivkin Radler LLP
Contact
more
less

Rivkin Radler LLP on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide