Porter, M.D. | Metro | Lifespan | |
Date breach filed | 2013 | 2011 | 2017 |
Date settled in 2020 | March 3 | July 23 | July 27 |
Fee | $100,000 | $25,000 | $1.04 million |
Misc. penalty | Corrective plan | Corrective plan | Corrective plan |
# affected individuals | 500 | 1,263 | 20,431 |
Type of breach | Improper disposal | Phishing | Theft of laptop |
Why a violation | · No risk analysis conducted · Failed to implement security measures | · No risk analysis conducted · Did not adhere to Security Rule · Did not provide training until 2016 | · Failure to encrypt · Lack of media/device controls · Absence of a business associate agreement (BAA) |