On Feb. 22, the United States Department of Health and Human Services’ Office for Civil Rights announced an unprecedented use of civil monetary penalties on a Maryland-covered entity for violation of the Health Insurance Portability and Accountability Act Privacy Rule in the amount of $4.3 million. Just two days later, on Feb. 24, HHS announced a $1 million HIPAA Privacy Rule settlement with a Massachusetts provider that breached patient information.
In a press release, HHS Secretary Kathleen Sebelius said that, “Ensuring that Americans’ health-information privacy is protected is vital to our health care system and a priority of this administration. The U.S. Department of Health and Human Services is serious about enforcing individual rights guaranteed by the HIPAA Privacy Rule.”
In its first-ever use of civil monetary penalties for a HIPAA Privacy Rule violation, HHS’ Office for Civil Rights investigated individual complaints that it received from patients of Cignet Health of Prince George’s County, Md., between September 2008 and October 2009 regarding Cignet’s alleged denial of access to medical records. The HIPAA Privacy Rule requires that a covered entity provide patients with a copy of their medical records within 30 (and no later than 60) days of the patient’s request.
HHS’ Office for Civil Rights found 41 violations and assessed $1.3 million in penalties for the violations. However, because Cignet refused to respond to Office for Civil Rights’ demand to produce records and was altogether uncooperative with the investigation, HHS declared that Cignet demonstrated “reckless indifference” by ignoring numerous requests for records and “willfully neglected” its obligation to cooperate with the office.
HHS ultimately had to obtain a subpoena for the records and was thereafter successful in obtaining a default judgment against Cignet. Cignet further failed to respond to Office for Civil Rights’ offers to submit written evidence that violations were due to reasonable cause and not willful negligence. The office assessed $3 million for the additional violations for a grand total of $4.3 million in penalties. This represents a fine of $50,000 for each day Cignet refused to respond to it from March 17, 2009 to April 7, 2010.
The $3 million fine represented the maximum penalty of $1.5 million per year allowable under the Health Information Technology for Economic and Clinical Health Act of 2009 (HITECH).
Just two days after the announcement of the financial penalties assessed against Cignet, HHS announced that it had entered into a resolution agreement with General Hospital Corp. and Massachusetts General Physicians Organization Inc., collectively known as Massachusetts General Hospital, whereby the hospital agreed to pay $1 million to settle potential violations.
The underlying incident involved Mass. General’s loss of the protected health information of 192 patients. A Mass. General employee removed from the hospital’s premises patient-encounter forms that included 66 patients’ names, dates of birth, medical-record numbers, health insurers and policy numbers, diagnoses and the names of the providers, in order to work on the cases from home.
In addition, the employee took home the practice’s daily office schedules for three days containing the names and medical-record numbers of additional patients. While commuting to work on the subway, the employee placed the files on the seat next to her and subsequently exited the subway and left the files on the seat in the subway. The files were never recovered.
In addition to the resolution agreement, Mass. General agreed to a corrective-action plan requiring it to implement a comprehensive set of policies and procedures, including training and monitoring measures, to ensure the protection of protected health information in the future.
Whether or not the timing of the resolution agreement with Mass. General and the civil monetary penalties assessed against Cignet were coincidental or intentional, the message is clear that HIPAA-covered entities and business associates need to take HIPAA and HITECH compliance seriously. •
Linn Freedman is a health-services partner in Nixon Peabody LLP’s Providence office.
Beyond Cash Donations: How New Forms of Giving Are Transforming Not-for-Profit Accounting
Evolving Funding Landscape for Not-for-Profits Not-for-profit organizations are being asked to do more with less,…
Learn More












