Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Privacy & Compliance

Alaska Fined $1.7 Million for HIPAA Violations

The Alaska Department of Health and Social Services (DHSS) has agreed to pay a $1.7 million federal fine to settle possible violations of the Health Insurance Portability and Accountability Act of 1996 (HIPAA).

As part of their agreement with the U.S. Department of Health and Human Services (HHS), Alaska’s DHSS has also agreed to revise, review and maintain policies and procedures meant to keep the agency in compliance.

The Alaska Department of Health and Social Services (DHSS) has agreed to pay a $1.7 million federal fine to settle possible violations of the Health Insurance Portability and Accountability Act of 1996 (HIPAA).

As part of their agreement with the U.S. Department of Health and Human Services (HHS), Alaska’s DHSS has also agreed to revise, review and maintain policies and procedures meant to keep the agency in compliance.

“Covered entities must perform a full and comprehensive risk assessment and have in place meaningful access controls to safeguard hardware and portable devices,” said Leon Rodriguez, director of the HHS Office for Civil Rights (OCR), in a statement.  “This is OCR’s first HIPAA enforcement action against a state agency and we expect organizations to comply with their obligations under these rules regardless of whether they are private or public entities.”

Rodriguez’s office began its investigation following a breach report submitted by Alaska DHSS. The report indicated that a USB drive possibly containing sensitive medical information was stolen from the vehicle of a DHSS employee. During the investigation, OCR found that the state agency did not have adequate procedures in place to safeguard information, and had not completed a risk analysis, implemented risk management measures or completed security training for its workforce. It had also not implemented device and media controls or addressed device and media encryption as required by HIPPA, according to HHS.

As part of the settlement, a monitor will report back to OCR regularly on the state’s ongoing compliance efforts.

“The good news is no fraud has been reported related to the loss of this hard drive and this was an opportunity for HHS to discover the lack of compliance before another incident occurs,” blogged Chester Wisniewski, senior security advisor for Sophos Canada.

“Whatever type of sensitive information your organization gathers, the easiest way to ensure it isn’t stolen, leaked by hackers or accidentally discovered on an old USB key is to protect the information from the beginning,” he added. “Rather than worry about whether something is a mobile device or removable drive, encrypt it anyway. Base your decisions of what the information is, rather than where it is.”

Written By

Marketing professional with a background in journalism and a focus on IT security.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Healthcare cybersecurity firm Blackwell Security has named Geyer Jones as its first CEO.

Searchlight Cyber has appointed Tim Warner as VP of Global Enterprise Sales.

Morgan M. Adamski has been named the Executive Director of USCYBERCOM.

More People On The Move

Expert Insights

Related Content

Compliance

The three primary drivers for cyber regulations are voter privacy, the economy, and national security – with the complication that the first is often...

Cybersecurity Funding

Los Gatos, Calif-based data protection and privacy firm Titaniam has raised $6 million seed funding from Refinery Ventures, with participation from Fusion Fund, Shasta...

Privacy

Employees of Chinese tech giant ByteDance improperly accessed data from social media platform TikTok to track journalists in a bid to identify the source...

Privacy

Many in the United States see TikTok, the highly popular video-sharing app owned by Beijing-based ByteDance, as a threat to national security.The following is...

Mobile & Wireless

As smartphone manufacturers are improving the ear speakers in their devices, it can become easier for malicious actors to leverage a particular side-channel for...

Cloud Security

AWS has announced that server-side encryption (SSE-S3) is now enabled by default for all Simple Storage Service (S3) buckets.

Audits

The PCI Security Standards Council (SSC), the organization that oversees the Payment Card Industry Data Security Standard (PCI DSS), this week announced the release...

Application Security

Security researchers at Google’s Project Zero have picked apart one of the most notorious in-the-wild iPhone exploits and found a never-before-seen hacking roadmap that...