Lifespan pays over $1M to settle HIPAA charge

Providence, R.I.-based Lifespan will settle a potential HIPAA violation related to a stolen laptop for just over $1 million, according to an HHS news release.

Advertisement

On April 21, 2017, Lifespan Corp., the health system’s parent company and business associate, reported an employee’s unencrypted laptop had been stolen. The laptop included protected health information such as patient names, medical records and demographic information.

There were 20,431 individuals affected by the breach.

The Office for Civil Rights conducted an investigation and found the health system had systemic noncompliance with HIPAA rules, including failure to encrypt electronic protected health information as well as a lack of device and media controls. The health system also didn’t have a business associate agreement with Lifespan Corp..

Lifespan will undergo a corrective action plan and be monitored for two years as part of the settlement.

More articles on cybersecurity:
University of Utah Health reports data breach affecting 10,000 patients
CVS Pharmacy loses 21,289 patients’ information after vandalism
North Carolina medical clinic to pay $25K settlement over multiple HIPAA violations

At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.

Register to Attend Webinar

What clinicians need from AI after the pilot: Lessons from Adventist Health and Rady Children’s

Friday, July 24
12:00 PM - 1:00 PM CDT

Presenters: Dr. Dieter Sumerauer, Rady Children’s HealthDr. Salman Naqvi, AdventistDr. Reid Conant, Abridge

Advertisement

Next Up in Cybersecurity

Advertisement

Comments are closed.