Kinney & Larson, LLP
  • Home
  • About
  • Contact
  • Services
    • Affordable Care Act
    • HIPAA/HITECH
    • Contracts
    • Wellness
    • Consumer Plans/Accounts
    • General Compliance
  • Past Speeches
  • Blog
  • Disclaimer

Beware: A Copier Can Violate HIPAA

8/15/2013

1 Comment

 
by Phil Larson

HHS Settles with Health Plan in Photocopier Breach Case

Under a settlement with the U.S. Department of Health and Human Services (HHS), Affinity Health Plan, Inc. will settle potential violations of the HIPAA Privacy and Security Rules for $1,215,780.  OCR’s investigation indicated that Affinity impermissibly disclosed the protected health information of up to 344,579 individuals when it returned multiple photocopiers to a leasing agent without erasing the data contained on the copier hard drives. In addition, the investigation revealed that Affinity failed to incorporate the electronic protected health information stored in copier’s hard drives in its analysis of risks and vulnerabilities as required by the Security Rule, and failed to implement policies and procedures when returning the hard drives to its leasing agents.

  • Read the Resolution Agreement (PDF)

The settlement comes as the September 24, 2013 deadline for Covered Entities and their business partners (business associates) to update their processes to comply with changes to HIPAA’s regulations adopted by OCR earlier this year.

Please note, this issue is not confined to returning of printers/copiers.  If the device contains PHI, it is also subject to administrative, technical and physical safeguards under HIPAA where it stands.    

​If you need assistance with HIPAA compliance, please contact Kinney & Larson.​
1 Comment
roskisprinssin link
6/28/2023 11:57:17 pm

Great post thank youu

Reply



Leave a Reply.

    To Search Blog:

    Archives

    May 2021
    January 2019
    April 2018
    October 2017
    May 2017
    January 2017
    November 2016
    September 2016
    June 2016
    April 2016
    March 2016
    December 2015
    October 2015
    August 2015
    June 2015
    April 2015
    February 2015
    January 2015
    December 2014
    October 2014
    September 2014
    August 2014
    May 2014
    April 2014
    March 2014
    February 2014
    January 2014
    December 2013
    November 2013
    October 2013
    September 2013
    August 2013
    July 2013

    Categories

    All
    90 Day Waiting Period
    Adult Children
    Affordable
    Automatic Enrollment
    COBRA
    Communications
    Employer Fair Share
    Exchanges Or State Issues
    HIPAA Privacy / HITECH
    Individual Mandate
    Nondiscrimination/Wellness
    Plan Design
    Taxes And Fees

About       Contact       Disclaimer