Earlier this year, Health Department officials in Multnomah County, Oregon discovered an employee set up an automatic mail forwarder that resulted in a HIPAA violation. The employee in question configured their work email account to automatically forward all email to a personal Gmail account. As we've previously covered, when it comes to Gmail and HIPAA compliance, the two don't mix. In a nutshell, Google is willing to sign a Business Associate Agreement (BAA) for use with some, but not all, of their services.
Google does not offer a BAA for Gmail.com accounts.
SEE RELATED: How to Make Gmail HIPAA Compliant
The employee who committed the HIPAA violation works in the Multnomah County Health Department. That means emails sent to that person's work email were automatically forwarding the following protected health information ( PHI):
The HIPAA violation was found during a random audit in November 2016. A subsequent internal investigation found that:
Although the County confirmed that the gmail account had deleted, the possibility that PHI was inappropriately accessed could not be ruled out.
It is unclear why the emails were forwarded to the employee's gmail account. Although it may have been an innocent mistake, it still represents a HIPAA violation.
SEE ALSO: Lack of Email DLP causes HIPAA Violation in California