CMS contractor fined $300K over screenshot breach

A CMS contractor has agreed to pay a $306,722 fine for not securing screenshots of patient data.

Advertisement

ASRC Federal Data Solutions LLC, which provides Medicare support services, and a subcontractor stored screenshots from CMS systems containing personally identifiable information and possibly personal health data of Medicare beneficiaries, violating contractual cybersecurity requirements, according to the settlement agreement.

A third party improperly accessed the subcontractor’s server in 2022 using authorized credentials, allegedly breaching the unencrypted screenshots.

“Safeguarding patients’ sensitive personal information is of paramount importance,” said Stephen Niemczak, special agent in charge of HHS’ Office of the Inspector General, in an Oct. 15 statement. “This settlement demonstrates the commitment by HHS-OIG and our law enforcement partners to use every available tool to protect the healthcare data of all Americans.”

At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.

Advertisement

Next Up in Cybersecurity

Advertisement

Comments are closed.