On April 21, 2017, Lifespan Corporation filed a breach report with the Office for Civil Rights ( OCR) at the U.S. Department of Health and Human Services ( HHS) concerning the theft of a hospital employee’s laptop containing electronic protected health information ( ePHI) including: patients’ names, medical record numbers, demographic information, and medication information. The breach affected 20,431 individuals. Lifespan Corporation is the parent company and business associate of Lifespan Health System Affiliated Covered Entity (Lifespan ACE). However, OCR's investigation also found that Lifespan ACE failed to have a business associate agreement ( BAA) in place with Lifespan Corporation.
We recommend a two-pronged approach to avoid such high HIPAA fines due to stolen laptops.
As one option, Microsoft provides BitLocker for free with certain versions of Windows. SEE ALSO: Free Windows Encryption tools for HIPAA Compliance The MacOS also includes a utility called FileVault 2 to encrypt the contents of a hard drive. SEE ALSO: Free Disk Encryption for Mac OS
In today’s society employees, regardless of profession, will take their work home with them. Just like everyone else, employees of covered entities need to be able to send secure email anytime, anywhere. SEE ALSO: Cybersecurity Challenges of Remote Working That’s where Paubox comes in. Paubox Email Suite allows users to send HIPAA compliant email directly to patient's email boxes, no passwords or portals required. It integrates directly with a customer's existing email provider, so users do not need to change their workflow in any way to maintain HIPAA compliance. In addition, Paubox will sign a BAA with any and all customers. Paubox Email Suite Premium offers additional features, such as inbound email security to protect against email spoofing, phishing attempts, and malware attacks. It also includes email data loss prevention tools which ensure that employees do not send sensitive or critical information outside of a corporate network. We understand the HIPAA landscape and we are here to help with your compliance needs.