The Department of Health and Human Services settles with Illinois health network over late breach notification
Posted in HIPAA/HITECH
For the first time, the Department of Health and Human Services (HHS) has settled potential violations of the HIPAA Breach Notification Rule for not abiding by the reporting deadline.
HIPAA's Breach Notification Rule requires organizations to notify affected individuals, certain media and HHS within 60 days of the discovery of a breach. But that deadline was not met by Presence Health Network, a large Illinois-based health network, after it uncovered a data breach on Oct. 22, 2013, affecting more than 800 individuals. Instead, Presence Health waited to report the breach to those affected individuals until Feb. 3, 2014 (104 days after discovery of the breach), according to HHS. Each day Presence Health failed to notify each affected individual of the breach constitutes a separate violation of the Breach Notification Rule. See 45 C.F.R. § 164.404(b).
On Jan. 9, 2017, after an investigation, HHS announced that an agreement with Presence Health was reached concerning the late notification and potential HIPAA violations. Under the agreement, Presence Health will pay HHS $475,000 and enter into and comply with a Corrective Action Plan (CAP). The CAP is an eight-page plan that outlines certain obligations that Presence Health must meet for a two-year period. Some of those obligations are to: (1) revise existing policies and procedures; (2) report those revisions to HHS for review and approval; (3) conduct HHS-approved training and retraining to network members; and (4) retain documents showing compliance with the CAP for a period of six years and make the documents available on request.
The agreement states that Presence Health did not admit liability and that HHS did not concede that Presence Health did not violate HIPAA.
The HHS press release, and the Resolution Agreement and Corrective Action Plan, are here.
