By
OCD Tech
July 6, 2016
•
3
min read
In a landscape-shaping turn of events, the first HIPAA Business Associate has been required to face and pay a $650,000 fine due to its inability to safeguard protected health information (PHI) and electronic protected health information (ePHI). Catholic Health Care Services of the Archdiocese of Philadelphia (CHCS) has agreed to settle and pay this substantial penalty after 412 individuals’ PHI was compromised because of the theft of an organization-issued mobile device which was not password protected. The compromised information belonged to nursing home patients from six nursing home facilities around Philadelphia.The enormity of the fine stems from CHCS’ lack of controls in place to prevent an incident such as this. It was apparent to the Office of Civil Rights (OCR) during the investigation that CHCS had no formal policies discussing the removal of mobile devices containing PHI or the organization’s response to a security incident. In addition, it was noted by OCR that CHCS had not performed a risk analysis or implemented a risk management plan. All of these items are in violation of the HIPAA Security Rule. It appears that the compromised ePHI included Social Security numbers, diagnosis and treatment information, medical procedures, medication information and the names of family members and legal guardians.In determining the resolution amount, OCR determined that “CHCS provides unique and much-needed services in the Philadelphia region to the elderly, developmentally disabled individuals, young adults aging out of foster care, and individuals living with HIV/AIDS.” Had the organization not been deemed such a valuable service provider, the fines may have been even greater.If you have any questions regarding OCR’s decision, the settlement, or the fine, please contact:Michael Hammond, CISA, CISSP, CRISC, C|EHDirector, IT Audit Services at mhammond@ocd-tech.comorW. Jackson Schultz, CISASenior IT Audit & Security Consultant at jschultz@ocd-tech.com

Audit. Security. Assurance.
IT Audit | Cybersecurity | IT Assurance | IT Security Consultants – OCD Tech is a technology consulting firm serving the IT security and consulting needs of businesses in Boston (MA), Braintree (MA) and across New England. We primarily serve Fortune 500 companies including auto dealers, financial institutions, higher education, government contractors, and not-for-profit organizations with SOC 2 reporting, CMMC readiness, IT Security Audits, Penetration Testing and Vulnerability Assessments. We also provide dark web monitoring, DFARS compliance, and IT general controls review.
Contact Info
OCD Tech
25 BHOP, Suite 407, Braintree MA, 02184
844-623-8324
https://ocd-tech.com
Follow Us
Videos
Check Out the Latest Videos From OCD Tech!
Services
SOC Reporting Services
– SOC 2 ® Readiness Assessment
– SOC 2 ®
– SOC 3 ®
– SOC for Cybersecurity ®
IT Advisory Services
– IT Vulnerability Assessment
– Penetration Testing
– Privileged Access Management
– Social Engineering
– WISP
– General IT Controls Review
IT Government Compliance Services
– CMMC
– DFARS Compliance
– FTC Safeguards vCISO