Kinney & Larson, LLP
  • Home
  • About
  • Contact
  • Services
    • Affordable Care Act
    • HIPAA/HITECH
    • Contracts
    • Wellness
    • Consumer Plans/Accounts
    • General Compliance
  • Past Speeches
  • Blog
  • Disclaimer

Outdated and Unsupported Software Leads to HIPAA Settlement

12/16/2014

0 Comments

 
By Phil Larson

The Department of Health and Human Services (HHS) continues to provide important reminders for covered entities and those businesses that receive protected health information (PHI) under HIPAA through recently announced settlement agreements.  

This month, Anchorage Community Mental Health Services, a nonprofit providing behavior health care services agreed to settle a potential HIPAA violation for 2,743 patients and their electronic PHI.  Malware on the provider system lead to a breach notification from compromised IT resources.  

While Anchorage Community Mental Health Services had HIPAA policies, an investigation by HHS concluded they were not followed.  The security incident was the direct result of the provider failing to identify and address basic risks, such as not regularly updating their IT resources with available patches and running outdated, unsupported software.  This meant their system was more susceptible to malware and other risks.

The provider settled for $150,000, the agreement also includes a corrective action plan and requires the provider to report on the state of its compliance to OCR for a two-year period. The Resolution Agreement can be found on the OCR website at:

Read the Resolution Agreement

This settlement is important because it shows that it is not enough to have all the right policies.  Those policies must be followed and systems reviewed for unmatched vulnerabilities and unsupported software that can leave PHI unprotected.  As the settlement reminds us, HIPAA is an ongoing scheme, not just a "one and done" compliance program.  If you need assistance with HIPAA, please contact Kinney & Larson.              


0 Comments



Leave a Reply.

    To Search Blog:

    Archives

    May 2021
    January 2019
    April 2018
    October 2017
    May 2017
    January 2017
    November 2016
    September 2016
    June 2016
    April 2016
    March 2016
    December 2015
    October 2015
    August 2015
    June 2015
    April 2015
    February 2015
    January 2015
    December 2014
    October 2014
    September 2014
    August 2014
    May 2014
    April 2014
    March 2014
    February 2014
    January 2014
    December 2013
    November 2013
    October 2013
    September 2013
    August 2013
    July 2013

    Categories

    All
    90 Day Waiting Period
    Adult Children
    Affordable
    Automatic Enrollment
    COBRA
    Communications
    Employer Fair Share
    Exchanges Or State Issues
    HIPAA Privacy / HITECH
    Individual Mandate
    Nondiscrimination/Wellness
    Plan Design
    Taxes And Fees

About       Contact       Disclaimer