The infertility center in February 2017 discovered that a hacker accessed a third-party server containing an EHR database. While the database was encrypted and not exposed, supporting documents containing patients’ names, birth dates, Social Security numbers, lab results and other information may have been accessible.
The breach affected 14,633 individuals and allowed multiple instances of unauthorized access to the clinic’s network between August 2016 and January 2017, according to the New Jersey attorney general.
The state’s consumer affairs division launched an investigation into the incident, resulting in allegations that the clinic violated HIPAA regulations as well as the New Jersey Consumer Fraud Act when it removed administrative and technological safeguards for protected health information.
In addition to the $495,000 payment, the settlement also requires the clinic to implement data security system reforms and new encryption protocols to prevent future breaches, according to the news release from the attorney general.
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.