In its first enforcement action against a state agency, the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) settled last month with Alaska’s Department of Health and Social Services (DHSS) for HIPAA security violations it reported as required by HITECH. DHSS entered into a settlement agreement and agreed to pay $1,700,000 after a USB hard drive (an electronic storage device) potentially containing electronic protected health information (ePHI) was stolen from the vehicle of a DHSS computer technician in October 2009.
The HITECH Breach Notification Rule requires covered entities to report a breach, an impermissible use or disclosure of ePHI, of 500 individuals or more to the Secretary of HHS and the media. Smaller breaches affecting less than 500 individuals must be reported to the Secretary of HHS annually. OCR investigates each breach of 500 individuals or more reported under HITECH. In this case, OCR reviewed DHSS’s written response, policies, procedures, information regarding training activities and documentation related to compliance with the Privacy and Security Rules, and conducted on-site interviews of the DHSS workforce. At the conclusion of its investigation, OCR found that DHSS did not...
Please see full publication below for more information.