The FTC’s investigation into Accretive’s data practices was sparked by a 2011 data breach, in which 23,500 patients’ data was compromised when a laptop was stolen from an employee’s car.
The FTC alleged Accretive created unnecessary risk by allowing employees to transport laptops with patient information in their cars, and by not ensuring employees’ computers contained only the patient information necessary for their job functions.
Under the terms of the settlement, Accretive must develop and deploy a comprehensive data security policy that will be evaluated initially and every two years by a certified third party. The settlement will be in effect for the next 20 years.
More Articles on Healthcare Settlements:
UPMC, Highmark Drop Lawsuits
Abbott Laboratories to Pay $5.5M to Settle Kickback Claims
HIPAA Breach Notification Violations Cost Physician Practice $150k
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.