Stolen USB drives continue to generate large HIPAA fines

As we’ve previously covered, stolen USB drives are a big liability for HIPAA entities. When we last covered it in 2014, we used public data to calculate that it costs an average of $925,000 in HIPAA fines per stolen thumb drive. That average is likely to go up.

This week the U.S. Department of Health and Human Services announced it issued a $2.2 million HIPAA fine for a stolen USB thumb drive. The affected entity is MAPFRE Life Insurance Company of Puerto Rico (MAPFRE).

Stolen USB Drives Continue to Generate Large HIPAA Fines - Paubox

USB drive stolen overnight

On 29 September 2011, MAPFRE filed a breach report with HHS indicating that a USB drive containing ePHI was stolen from its IT department, where the device was left overnight. The USB drive included names, birthdates and Social Security numbers of over 2,200 individuals.

A subsequent investigation by HHS revealed MAPFRE’s noncompliance with HIPAA regulations.

  • Failure to conduct a risk analysis and implement risk management plans, contrary to what was claimed earlier.
  • Failure to deploy encryption on its laptops and removable storage media until three years after the incident.
  • Failure or significant delay in implementing corrective measures.

USB Drives are a HIPAA Violation Waiting to Happen

Our stance on USB drives (thumb drives) remains the same: They do not belong in healthcare and are a HIPAA violation waiting to happen.

Here’s why:

  • They are easy to steal or misplace.
  • Hardware Encrypted USB Drives are hard to distinguish from non-encrypted drives.
  • Using software to encrypt a USB drive is beyond the ability of most users. In other words, they won’t do it.

We believe HIPAA violations like this will further push U.S. healthcare entities to adopt HIPAA compliant cloud storage technologies like Paubox.

About MAPRE

MAPFRE is a subsidiary company of MAPFRE S.A., a global multinational insurance company headquartered in Spain. MAPFRE underwrites and administers a variety of insurance products and services in Puerto Rico, including personal and group health insurance plans.

SEE ALSO: HIPAA Fines caused by Stolen Thumb Drives

Try Paubox Email Suite for FREE today.

About the author

Hoala Greevy

Founder CEO Paubox. Kayak fishing when I can.

Read more by Hoala Greevy

Get started with
end-to-end protection

Bolster your organization's security with state-of-the-art email encryption and inbound email security.

Highest rated HIPAA compliant messaging solution on G2

EmailEncryption BestMeetsRequirements MeetsRequirements
SecureEmailGateway MostImplementable Total
SecureEmailGateway Leader Leader
SecureEmailGateway EasiestToUse EaseOfUse
SecureEmailGateway EasiestAdmin EaseOfAdmin
SecureEmailGateway BestUsability Total
SecureEmailGateway BestResults Total
SecureEmailGateway BestRelationship Total
EmailEncryption UsersMostLikelyToRecommend Nps
EmailEncryption MomentumLeader Leader
SecureEmailGateway BestSupport Mid Market QualityOfSupport
EmailEncryption BestMeetsRequirements MeetsRequirements
SecureEmailGateway MostImplementable Total
SecureEmailGateway Leader Leader
SecureEmailGateway EasiestToUse EaseOfUse
SecureEmailGateway EasiestAdmin EaseOfAdmin
SecureEmailGateway BestUsability Total
SecureEmailGateway BestResults Total
SecureEmailGateway BestRelationship Total
EmailEncryption UsersMostLikelyToRecommend Nps
EmailEncryption MomentumLeader Leader
SecureEmailGateway BestSupport Mid Market QualityOfSupport