Fines show no tolerance for HIPAA violations

On Feb. 22, the United States Department of Health and Human Services’ Office for Civil Rights announced an unprecedented use of civil monetary penalties on a Maryland-covered entity for violation of the Health Insurance Portability and Accountability Act Privacy Rule in the amount of $4.3 million. Just two days later, on Feb. 24, HHS announced a $1 million HIPAA Privacy Rule settlement with a Massachusetts provider that breached patient information.
In a press release, HHS Secretary Kathleen Sebelius said that, “Ensuring that Americans’ health-information privacy is protected is vital to our health care system and a priority of this administration. The U.S. Department of Health and Human Services is serious about enforcing individual rights guaranteed by the HIPAA Privacy Rule.”
In its first-ever use of civil monetary penalties for a HIPAA Privacy Rule violation, HHS’ Office for Civil Rights investigated individual complaints that it received from patients of Cignet Health of Prince George’s County, Md., between September 2008 and October 2009 regarding Cignet’s alleged denial of access to medical records. The HIPAA Privacy Rule requires that a covered entity provide patients with a copy of their medical records within 30 (and no later than 60) days of the patient’s request.
HHS’ Office for Civil Rights found 41 violations and assessed $1.3 million in penalties for the violations. However, because Cignet refused to respond to Office for Civil Rights’ demand to produce records and was altogether uncooperative with the investigation, HHS declared that Cignet demonstrated “reckless indifference” by ignoring numerous requests for records and “willfully neglected” its obligation to cooperate with the office.
HHS ultimately had to obtain a subpoena for the records and was thereafter successful in obtaining a default judgment against Cignet. Cignet further failed to respond to Office for Civil Rights’ offers to submit written evidence that violations were due to reasonable cause and not willful negligence. The office assessed $3 million for the additional violations for a grand total of $4.3 million in penalties. This represents a fine of $50,000 for each day Cignet refused to respond to it from March 17, 2009 to April 7, 2010.
The $3 million fine represented the maximum penalty of $1.5 million per year allowable under the Health Information Technology for Economic and Clinical Health Act of 2009 (HITECH). This first use of civil monetary penalties for violations certainly brings attention to Cignet’s flagrant refusal to cooperate with HHS’ investigation but also serves as a warning to HIPAA-covered entities and business associates that HHS is serious about enforcement and is ready and willing to impose monetary penalties, as authorized by HITECH.
Just two days after the announcement of the financial penalties assessed against Cignet, HHS announced that it had entered into a resolution agreement with General Hospital Corp. and Massachusetts General Physicians Organization Inc., collectively known as Massachusetts General Hospital, whereby the hospital agreed to pay $1 million to settle potential violations.
The underlying incident involved Mass. General’s loss of the protected health information of 192 patients. A Mass. General employee removed from the hospital’s premises patient-encounter forms that included 66 patients’ names, dates of birth, medical-record numbers, health insurers and policy numbers, diagnoses and the names of the providers, in order to work on the cases from home.
In addition, the employee took home the practice’s daily office schedules for three days containing the names and medical-record numbers of additional patients. While commuting to work on the subway, the employee placed the files on the seat next to her and subsequently exited the subway and left the files on the seat in the subway. The files were never recovered.
In addition to the resolution agreement, Mass. General agreed to a corrective-action plan requiring it to implement a comprehensive set of policies and procedures, including training and monitoring measures, to ensure the protection of protected health information in the future.
Whether or not the timing of the resolution agreement with Mass. General and the civil monetary penalties assessed against Cignet were coincidental or intentional, the message is clear that HIPAA-covered entities and business associates need to take HIPAA and HITECH compliance seriously. &#8226


Linn Freedman is a health-services partner in Nixon Peabody LLP’s Providence office.

Rhode Island's Market Has Changed. Developers, Builders, Investors and Sellers Must Change With It.

By Emilio DiSpirito IV License Partner | Engel & Völkers Oceanside Leader | The DiSpirito…

Learn More

No posts to display