HHS issues first-ever HIPAA fine to small organization, for portable device data breach

Share this article:
Experts: Push EHR progress even if feds won't help pay
Experts: Push EHR progress even if feds won't help pay

The importance of security and strategies for the use of portable technology for small health organizations came to the forefront last week when the Department of Health and Human Services acknowledged it will receive a $50,000 settlement from an Idaho organization. The agreement came after allegations the group lost a laptop with health information for 441 patients.

The action is the first for a breach of protected health information for fewer than 500 individuals under the Health Insurance Portability and Accountability Act (HIPAA) Security Rule. The not-for-profit Hospice of North Idaho reported to the HHS Office for Civil Rights that an unencrypted laptop with patient information was stolen in June 2010.

OCR fined the hospice because it did not conduct a security risk analysis or have policies or procedures to address portable device security. The HIPAA regulation is meant to safeguard electronic patient health information.

Also, the hospice did not implement security measures to address the loss of patient health data or manage that risk. A federal official said that covered entities, regardless of size, must take action and will be held accountable for safeguarding patients' health information.

Since the incident, the Hayden-based Hospice of North Idaho has improved its HIPAA compliance program and entered a two-year corrective action plan as part of the settlement. The corrective action plan between OCR and the Hospice of North Idaho can be found here.

Share this article:

More in News

Congressman requests briefing on nursing home five-star rating system

Congressman requests briefing on nursing home five-star rating ...

A leader in Congress has called for an evaluation of the nursing home five-star rating system in light of a recent New York Times article. Rep. Elijah Cummings (D-MD) requested ...

CMS: Discharge assessments must be completed when residents transfer to a non-certified ...

Skilled nursing facilities must complete a discharge assessment when a resident is transferred from a certified to a non-certified bed, even if both beds are in the same building, the Centers for Medicare & Medicaid Services emphasizes in a recent memorandum.

Focusing on a single word might improve nursing home residents' quality of ...

An affordable, easily implemented relaxation technique could improve nursing home residents' psychological well-being. It also could potentially boost their immune systems, according to recently published findings.