
The Office for Civil Rights recently fined Aetna Life Insurance Company $1,000,000 for violating HIPAA on three different occasions.
What happened?
In 2017, Aetna reported three breaches to OCR.- In April 2017, Aetna exposed documents without login credentials which were subsequently indexed by search engines, exposing 5,002 individuals’ protected health information (PHI).
- In July 2017, Aetna sent letters with window envelopes. Besides displaying the name and address, they also showed private medical information. This breach affected almost 12,000 people.
- In September 2017, Aetna was conducting a research study and sent information to participants in the mail. The envelope contained the name and logo of the research study, which was an impermissible disclosure. 1,600 individuals were affected.
