[fusion_builder_container hundred_percent=”no” hundred_percent_height=”no” hundred_percent_height_scroll=”no” hundred_percent_height_center_content=”yes” equal_height_columns=”no” menu_anchor=”” hide_on_mobile=”small-visibility,medium-visibility,large-visibility” class=”” id=”” background_color=”” background_image=”” background_position=”center center” background_repeat=”no-repeat” fade=”no” background_parallax=”none” enable_mobile=”no” parallax_speed=”0.3″ video_mp4=”” video_webm=”” video_ogv=”” video_url=”” video_aspect_ratio=”16:9″ video_loop=”yes” video_mute=”yes” video_preview_image=”” border_size=”” border_color=”” border_style=”solid” margin_top=”” margin_bottom=”” padding_top=”” padding_right=”” padding_bottom=”” padding_left=””][fusion_builder_row][fusion_builder_column type=”1_1″ layout=”1_1″ spacing=”” center_content=”no” link=”” target=”_self” min_height=”” hide_on_mobile=”small-visibility,medium-visibility,large-visibility” class=”” id=”” background_color=”” background_image=”” background_position=”left top” background_repeat=”no-repeat” hover_type=”none” border_size=”0″ border_color=”” border_style=”solid” border_position=”all” padding=”” dimension_margin=”” animation_type=”” animation_direction=”left” animation_speed=”0.3″ animation_offset=”” last=”no”][fusion_text]

2017 will go down as a change year for Health Insurance Portability and Accountability Act (HIPAA) enforcement of the Privacy, Security, and Breach Notification Rules. This comes on the heels of 2016, which saw an unprecedented level of enforcement actions, with 13 total settlements and nearly a 300% increase in total collected fines over 2015. In 2017, nine compliance reviews were settled with resolution agreements in addition to a HIPAA enforcement action in which a civil monetary penalty was levied. A total of $19.4 million in fines and penalties were collected in 2017 by OCR through its enforcement actions.

OCR’s enforcement approach has quietly undergone a significant change by resolving enforcement actions informally when the covered entity or business associate corrects its compliance problems, and without the government levying fines or penalties for HIPAA violations. In 2017, over 800 cases will be closed through use of this informal enforcement approach. The number case closures in 2017 through an informal resolution increased by 10% over the number in 2016.

What Did We Learn from OCR HIPAA Enforcement Actions in 2017?

Several themes emerged from OCR enforcement actions that covered entities and business associates should keep in mind to help ensure their compliance with the HIPAA requirements.

2017 OCR HIPAA Enforcement Fines and Penalties

[/fusion_text][fusion_table]

Organization Fine Total Link to OCR Settlement
Presence Health $475,000 First HIPAA enforcement action for lack of timely breach notification
MAPFRE $2,200,000 HIPAA settlement demonstrates importance of implementing safeguards for ePHI
Children’s Medical Center of Dallas $3,200,000 Lack of timely action risks security and costs money
Memorial Healthcare System $5,500,000 $5.5 million HIPAA settlement shines light on the importance of audit controls
Metro Community Provider Network $400,000 Overlooking risks leads to breach, $400,000 settlement
Center for Children’s Digestive Health $31,000 No Business Associate Agreement? $31K mistake
CardioNet $2,500,00 $2.5 million settlement shows that not understanding HIPAA requirements creates risk
Memorial Hermann Health System $2,400,000 Texas health system settles potential HIPAA violations for disclosing patient information
St. Luke’s Roosevelt Hospital System $387,200 Careless handling of HIV information jeopardizes patient’s privacy, costs entity $387K
21st Century Oncology $2,300,000 Failure to protect the health records of millions of people costs entity millions of dollars
2017 Total: $19,393,200

[/fusion_table][/fusion_builder_column][fusion_builder_column type=”1_1″ layout=”1_1″ spacing=”” center_content=”no” link=”” target=”_self” min_height=”” hide_on_mobile=”small-visibility,medium-visibility,large-visibility” class=”” id=”” background_color=”” background_image=”” background_position=”left top” undefined=”” background_repeat=”no-repeat” hover_type=”none” border_size=”0″ border_color=”” border_style=”solid” border_position=”all” padding_top=”” padding_right=”” padding_bottom=”” padding_left=”” margin_top=”20px” margin_bottom=”” animation_type=”” animation_direction=”left” animation_speed=”0.3″ animation_offset=”” last=”no”][fusion_text]

Only You Can Prevent HIPAA Enforcement Actions

Healthcare providers, health plan administrators, and business associates should take measures now to identify and fix the gaps that threaten the confidentiality or security of their PHI. In addition, steps to review and replace policies and procedures that are out-of-date or that no longer align to the organization’s business or information system operations. Some best practices to prepare now include:

Please contact us if you have any questions or need help assessing your HIPAA compliance or information security preparedness.

[/fusion_text][/fusion_builder_column][/fusion_builder_row][/fusion_builder_container]