Skip to the main content.
Talk to sales Start for free
Talk to sales Start for free

2 min read

OCR HIPAA enforcement continues during pandemic

OCR HIPAA enforcement continues during pandemic
HIPAA Act logo The U.S. Department of Health and Human Services (HHS) Office for Civil Rights’ (OCR) HIPAA enforcement continues during the pandemic. This year, OCR has already settled with three covered entities (CEs) following investigations into their reported breaches. Such settlements remind healthcare organizations of the importance of HIPAA compliance and strong cybersecurity even during health crises.

What is HIPAA?

HIPAA is U.S. legislation created to improve health coverage standards and combat abuse related to protected health information (PHI). SEE ALSO: What is HIPAA? Or is it HIPPA? Most commonly associated with HIPAA are Title II and its significant provisions: CEs and their business associates (BAs) are HIPAA compliant if they make a concerted effort to protect PHI from a breach. And while a breach does not always result in a HIPAA violation penalty, any breach that affects more than 500 people must be reported to OCR for investigation, and it will be published on HHS' Breach Portal, aka the " wall of shame." OCR then decides if the CE is at fault, as is the circumstance in the three cases settled this year.

 

Recent OCR settlements

Fees for the three recently settled cases— Steven A. Porter, M.D., Metropolitan Community Health Services, and Lifespan Health System Affiliated Covered Entity—total almost $1.2 million.
  Porter, M.D. Metro Lifespan
Date breach filed 2013 2011 2017
Date settled in 2020 March 3 July 23 July 27
Fee $100,000 $25,000 $1.04 million
Misc. penalty Corrective plan Corrective plan Corrective plan
# affected individuals 500 1,263 20,431
Type of breach Improper disposal Phishing Theft of laptop
Why a violation ·   No risk analysis conducted ·   Failed to implement security measures ·   No risk analysis conducted ·   Did not adhere to Security Rule ·   Did not provide training until 2016 ·   Failure to encrypt ·   Lack of media/device controls ·   Absence of a business associate agreement (BAA)
In general, OCR focused on the lack of security as related to: Each CE could have avoided the violation by implementing security measures, if not from the beginning, then as soon as their problem was discovered. According to OCR Director, Roger Severino, “Providers owe it to their patients to quickly address problem areas to safeguard individuals’ health information.”

 

Accountability and security

Without enforcement, compliance may not be a top priority, especially during a pandemic; accountability ensures strong cybersecurity. And as stated by HHS in the past, HIPAA and compliance reviews are never suspended. OCR modified certain rules recently around the usage of telehealth, COVID-19 testing sites, and communication, but HIPAA compliance is still necessary. Especially as safety concerns grow with increased remote working, telehealth, and telecommunication. Emphasis must be on strong procedures and policies, employee awareness training, and solid email security (i.e., HIPAA compliant email). Paubox Email Suite encrypts all emails sent from a customer’s existing email platform. Emails are delivered directly to a patient’s inbox with no extra steps or passwords required. Paubox Email Suite is perfect for helping CEs avoid a HIPAA violation when protection is needed the most.
 
Try Paubox Email Suite for FREE today.

Subscribe to Paubox Weekly

Every Friday we'll bring you the most important news from Paubox. Our aim is to make you smarter, faster.