Affinity filed the breach report with HHS’ Office for Civil Rights after being informed by the next company to lease one of the photocopiers that patient data remained on the hard drive, as required under the HITECH Act. Up to 344,579 individuals may have been affected, according to the breach report and subsequent HHS investigation.
In addition to the payment of $1.2 million, the terms of the settlement also require Affinity to do its best to recover all the hard drives containing PHI and implement new information safeguarding measures.
More Articles on HIPAA:
15 Things to Know About the HIPAA Omnibus Final Rule Before Sept. 23
Study: Cyber Insurance on the Rise (And How It May Not Be Enough)
10 Ways to Ensure HIPAA Compliance on Social Media
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.