While investigating a data breach in which a portable electronic storage device that may have contained electronic personal health information was stolen from the vehicle of a DHSS employee, HHS found that the department did not have adequate policies and procedures in place to safeguard ePHI. According to the report, evidence suggested that DHSS had not completed a risk analysis, implemented sufficient risk management measures, conducted security training for its workforce members, established device and media controls or addressed device and media encryption.
More Articles on HIPAA Violations:
3 Considerations for Evaluating Data Breach Insurance Policies
5 Steps to Achieving HIPAA Compliance
Phoenix Cardiac Surgery Group Pays $100K in HIPAA Violation Settlement
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.