UCMC agreed to the settlement for violating the HIPAA Right of Access standard, which requires providers to give patients access to their health records quickly and without being overcharged. The settlement marks OCR’s 12th under the initiative since closing its first case in September 2019.
OCR received a complaint in May 2019 from a UCMC patient claiming that the hospital failed to send an electronic copy of her medical records to her layers. The patient made the request Feb. 19, 2019.
OCR launched an investigation and determined that UCMC failed to timely provide a copy of the patient’s medical records, which violated the HIPAA rules deeming that patients have the right to request electronic copies of their records in the EHR be sent directly to a third party. The patient received her records in August 2019.
In addition to the financial settlement, UCMC will undergo a corrective action plan and two years of monitoring by OCR.
More articles on cybersecurity:
LSU Health email hack exposes patient information: 4 details
Ohio hospital still bringing computers back online 2 months after IT incident
Top US cybersecurity official fired: 4 details
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.