Health Law Alert: HITECH Breach Enforcement Announced: BCBS Settles with OCR for $1.5 Million

Baker Donelson
Contact

Blue Cross and Blue Shield of Tennessee (BCBST) will pay $1.5 million and enter into a Corrective Action Plan with the Department of Health and Human Services Office for Civil Rights (OCR) to settle OCR's investigation into BCBST's violations of the HIPAA Security Rule. Sarah Swank and Joshua Freemire review the genesis of the settlement and discuss the lessons other covered entities can learn from it.

Increased enforcement is a key message from the Department of Health and Human Services Office for Civil Rights (OCR). Since the start of 2012, OCR has publicized settlements with three entities: two of which concerned civil rights violations under section 504 of the Rehabilitation Act and the most recent of which concerned violations of the HIPAA Security Rule. On March 13, 2012, OCR issued a press release detailing its settlement with Blue Cross and Blue Shield of Tennessee (BCBST), under which BCBST agreed to pay $1.5 million and enter into a 450-day Corrective Action Plan (CAP) to address its HIPAA compliance issues. BCBST settled following an investigation triggered by the report of a "breach" — 57 unencrypted hard drives, including patient records for over a million patients, were stolen from a leased facility in Tennessee.

Please see full publication below for more information.

LOADING PDF: If there are any problems, click here to download the file.

Written by:

Baker Donelson
Contact
more
less

Baker Donelson on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide