On February 6, the U.S. Department of Health and Human Services (“HHS”), Office of Civil Rights (“OCR”), announced that it had settled a cybersecurity investigation with Montefiore Medical Center (“Montefiore”), a non-profit hospital system based in New York City, for $4.75 million.  As brief background, OCR is responsible for administering and enforcing the Health Insurance Portability and Accountability Act of 1996, as amended, and its implementing regulations (collectively, “HIPAA”).  Among other things, HIPAA requires that regulated entities take steps to protect the privacy and security of patients’ protected health information (“PHI”).

In 2015, Montefiore was alerted that there was evidence of theft of a specific patient’s medical information.  After an internal investigation, Montefiore discovered that one of their employees stole the electronic PHI (“ePHI”) of 12,517 patients and sold the information to an identity theft ring.  OCR’s subsequent investigation of Montefiore revealed multiple potential violations of HIPAA, such as failures by Montefiore “to analyze and identify potential risks and vulnerabilities to” PHI and “to implement policies and procedures that record and examine activity in information systems containing or using” PHI.  According to OCR, the lack of safeguards caused Montefiore to be unable to prevent the cyberattack or “even detect” that the cyberattack had happened until years later.   

In addition to paying $4.75 million to OCR, Montefiore must implement a corrective action plan to secure and protect PHI.  Under the action plan, Montefiore will have to:

  • Conduct an accurate and thorough assessment of the potential security risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI;
  • Develop a written risk management plan to address and mitigate security risks and vulnerabilities identified;
  • Develop a plan to implement hardware, software, and/or other procedural mechanisms that record and examine activity in all information systems that contain or use ePHI;
  • Review and revise, if necessary, written policies and procedures to comply with HIPAA; and
  • Provide training to its workforce on HIPAA policies and procedures.

OCR will monitor Montefiore “for two years to ensure compliance with the law.”  OCR Director Melanie Fontes Rainer noted that this “investigation and settlement with Montefiore are an example of how the health care sector can be severely targeted by cyber criminals and thieves—even within their own walls . . . and it’s incumbent that our health care system follow the law to protect patient records.”

While announcing the settlement, OCR also reminded HIPAA-regulated entities of their obligations to mitigate and prevent cyber threats.  OCR provided general recommendations for HIPAA-regulated entities, including:

  • Reviewing all vendor and contractor relationships to ensure all required business associate agreements are in place and address breach/security incident reporting obligations.
  • Integrating risk analysis and risk management into business processes, and ensuring that such processes are conducted regularly, especially when new technologies and business operations are planned.
  • Implementing regular review of information system activity.
  • Utilizing multi-factor authentication to ensure only authorized users are accessing PHI.
  • Encrypting PHI to guard against unauthorized access.
  • Incorporating lessons learned from previous incidents into the overall security management process.
  • Providing training specific to organization and job responsibilities and on regular basis and reinforcing workforce members’ critical role in protecting privacy and security.
Print:
Email this postTweet this postLike this postShare this post on LinkedIn
Photo of Anna D. Kraus Anna D. Kraus

Anna Durand Kraus advises on issues relating to the complex array of laws governing the health care industry. Her background as Deputy General Counsel to the U.S. Department of Health and Human Services (“HHS”) gives her broad experience with, and valuable insight into…

Anna Durand Kraus advises on issues relating to the complex array of laws governing the health care industry. Her background as Deputy General Counsel to the U.S. Department of Health and Human Services (“HHS”) gives her broad experience with, and valuable insight into, the programs and issues within the purview of HHS, including Medicare, Medicaid, fraud and abuse, and HIPAA privacy and security. Anna is co-chair of the firm’s Health Care Industry practice group.

Anna regularly advises clients on Medicare reimbursement matters, particularly those arising under Part B and the Part D prescription drug benefit. She also has extensive experience with the Medicaid Drug Rebate program. She assists numerous pharmaceutical and device manufacturers, health care providers, pharmacy benefit managers, and other health care industry stakeholders to navigate the challenges and opportunities presented by the Affordable Care Act.

Anna is a trusted adviser on health information privacy, security and breach notification issues, including those arising under the Health Insurance Portability and Accountability Act (“HIPAA”) and the Health Information Technology for Economic and Clinical Health (“HITECH”) Act. Her background in this area dates back to the issuance of the original HIPAA privacy regulations.

Anna’s clients depend on her to guide them through compliance with the Anti-Kickback statute, the Stark regulations, and other laws preventing fraud and abuse in the health care industry. Her deep knowledge of these laws has made her an important component of the firm’s representation of pharmaceutical companies and health care organizations under federal investigation or facing allegations under the False Claims Act. In addition, clients contemplating acquisitions in the health care sector rely on her to guide due diligence efforts.

Photo of Jorge Ortiz Jorge Ortiz

Jorge Ortiz is an associate in the firm’s Washington, DC office and a member of the Data Privacy and Cybersecurity and the Technology and Communications Regulation Practice Groups.

Jorge advises clients on a broad range of privacy and cybersecurity issues, including topics related to…

Jorge Ortiz is an associate in the firm’s Washington, DC office and a member of the Data Privacy and Cybersecurity and the Technology and Communications Regulation Practice Groups.

Jorge advises clients on a broad range of privacy and cybersecurity issues, including topics related to privacy policies and compliance obligations under U.S. state privacy regulations like the California Consumer Privacy Act.