Hospitals & Health Systems Newsletter - Fall 2012
November 18, 2012
On September 17, 2010, the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) announced that it had entered into a resolution agreement (i.e., settlement) with Massachusetts Eye and Ear Infirmary and Massachusetts Eye and Ear Associates (collectively, MEEI) which required MEEI to pay $1.5 million to OCR and enter into a three-year corrective action plan with the agency. The agreement related to the threat of a laptop belonging to an MEEI-affiliated physician while the physician was lecturing in South Korea in 2010. Although the laptop included certain data security features, it was not encrypted. The laptop reportedly held protected health information (PHI) for more than 3,600 of MEEI’s patients.
Unfortunately, the MEEI breach involves facts that are becoming all too familiar as hospitals and other “covered entities” struggle to maintain the privacy and security of their patients’ personal information, as required by the Health Insurance Portability and Accountability Act of 1996 (HIPAA). To continue reading, click the button below:
Categorized In
Latest Insights
- 2025 Estate & Gift Tax Planning Opportunities
- Despite Supreme Court Action, CTA Enforcement Remains Delayed
- Ten (Non-Tax) Reasons to Have an Estate Plan
- Not So Fast: Fifth Circuit Panel Vacates Prior Order; Reinstates Nationwide Injunction of CTA
- Corporate Transparency Act Update: Enforcement Deadlines Return Upon Dissolution of Nationwide Injunction