Have you created a ShazzleMail account on your smartphone? This is a required first step.

Yes No

Free Encrypted Email

08e4fdf7-1b6d-4784-8868-d224dc881485

Children’s Dallas docked $3.2 million over patient privacy breaches

February 2, 2017

Children’s Medical Center of Dallas has paid a penalty of more than $3.2 million to the federal government over privacy breaches dating back to 2007 that left the data for thousands of patients at risk.
The facility voluntarily reported potential disclosures of patient health information, but it did not implement strong safeguards to ensure that the breaches would not happen again, according to a statement issued Wednesday from the U.S. Department of Health and Human Services.
Ensuring security precautions to protect health information is essential, said Robinsue Frohboese, acting director of the Office for Civil Rights in the statement.

“A lack of risk management not only costs individuals the security of their data, but it can also cost covered entities a sizable fine,” she said.

Children’s Health responded Thursday saying that it has fully cooperated with the government’s investigation, and that it does not believe any patient or their family was affected by the incidents.
In 2010, the medical center reported that the personal information for about 3,800 patients had been accessible on an unencrypted, non-password protected BlackBerry device used at the Dallas-Fort Worth International Airport the previous year.
However, according to the federal investigation, they were aware of the potential risk of that kind of incident since at least 2007. A security analysis conducted by the healthcare consulting firm Strategic Management Systems over a 3-month period ending February 2007 uncovered gaps.
So did a separate analysis in 2008 from the consulting firm PwC. It said encryption should be a “high priority” for the medical center, as stolen devices could put patient data at risk.

Still, no security plan was established, and the encryption issue was not corrected on laptops, workstations and other devices distributed to the Children’s workforce until April 2013, the civil rights office investigation found.
That month a laptop was stolen in a separate breach that contained unencrypted data for nearly 2,500 people. Children’s reported the HIPAA (Health Insurance Portability and Accountability Act) violation to the Office of Civil Rights three months later.
In January, the medical center declined its right to request a hearing and challenge the fine, which totaled $3,217,000.
“We have decided to pay the imposed fine because efforts to formally contest the claims would be a long and costly distraction from our mission to make life better for children,” said Scott Summerall, a spokesperson for Children’s Health. “We remain committed to protecting the privacy of our patients.”

Tags: , , ,

Introducing ShazzleMail Email and How it Works

Privacy is your Fundamental Human Right.

Our Daily Blog
20190323_fbd001
Big tech faces competition and privacy concerns in Brussels
March 25, 2019

And the sector may be the better for it Print edition | Briefing Mar 23rd 2019 | PARIS Around 19 ...

Read more
telegram-3m
Telegram gets 3M new signups during Facebook apps’ outage
March 19, 2019

Natasha Lomas@riptari / 5 days ago Messaging platform Telegram claims to have had a surge in signup...

Read more
privacy-coins-and-bitcoin-dominance-guide
Apple tied to new privacy website, suggesting future security marketing
March 6, 2019

The iPhone maker, which makes privacy a selling point for its devices, appears to be gearing up for ...

Read more
images-1
US legal eagle: Well done, you bought privacy compliance tools. Doesn’t mean you comply with anything
February 25, 2019

From California state regs to Europe's GDPR: It's all just a 'veneer of protection' By Rebecca Hi...

Read more
imrs
Give To Get: Sensing, Tracking And Your Privacy
February 11, 2019

226 viewsFeb 10, 2019, 06:00pm By Tracy Brower: I write about the changing nature of work, workers ...

Read more