$2.3 Million Settlement in Unprotected Health Records Case

21st Century Oncology, Inc. determined that 2,213,597 individuals were affected by impermissible access to their names, social security numbers, physicians' names, diagnoses, treatment, and insurance information.

21st Century Oncology, Inc. has agreed to pay $2.3 million in lieu of potential civil money penalties to the U.S. Department of Health and Human Services Office for Civil Rights and to adopt a comprehensive corrective action plan to settle potential violations of the Health Insurance Portability and Accountability Act (HIPAA) Privacy and Security Rules, HHS recently announced.

Based in Fort Myers, Fla., 21CO is a provider of cancer care services and radiation oncology. With their headquarters located in Fort Myers, Florida, 21CO operates and manages 179 treatment centers, including 143 centers located in 17 states and 36 centers located in seven countries in Latin America. On May 25, 2017, 21CO filed for Chapter 11 bankruptcy protection; the settlement with HHS will resolve its claims against 21CO, and the corrective action plan will ensure that the reorganized entity emerges from bankruptcy with a strong HIPAA compliance program in place, according to HHS.

It reported that the settlement with the Office for Civil Rights was approved by a bankruptcy judge on Dec. 11, 2017.

According to HHS, on two occasions in 2015, the FBI notified 21CO that patient information was illegally obtained by an unauthorized third party and produced 21CO patient files purchased by an FBI informant. "As part of its internal investigation, 21CO determined that the attacker may have accessed 21CO's network SQL database as early as October 3, 2015, through the remote desktop protocol from an exchange server within 21CO's network. 21CO determined that 2,213,597 individuals were affected by the impermissible access to their names, social security numbers, physicians' names, diagnoses, treatment, and insurance information."

The OCR investigation found 21CO failed to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of the electronic protected health information; failed to implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level; failed to implement procedures to regularly review records of information system activity, such as audit logs, access reports, and security incident tracking reports; and disclosed protected health information to third-party vendors without a written business associate agreement.

"People need to trust that their private health information will remain exactly that: private," said OCR Director Roger Severino. "It's not just my hope that covered entities will learn from this example and proactively find and address their security risks, it's what the law requires."

The corrective action plan requires 21CO to complete a risk analysis and risk management plan, revise policies and procedures, educate its workforce on policies and procedures, provide all maintained business associate agreements to OCR, and submit an internal monitoring plan.

The resolution agreement is available here.

Product Showcase

  • Magid® D-ROC® GPD412 21G Ultra-Thin Polyurethane Palm Coated Work Gloves

    Magid’s 21G line is more than just a 21-gauge glove, it’s a revolutionary knitting technology paired with an advanced selection of innovative fibers to create the ultimate in lightweight cut protection. The latest offering in our 21G line provides ANSI A4 cut resistance with unparalleled dexterity and extreme comfort that no other 21-gauge glove on the market can offer! Read More

  • Safety Shower Test Cart

    The Safety Shower Test Cart speeds up and simplifies emergency shower tests, ensures you stay in compliance with OSHA regulations, and significantly reduces testing costs. With 7 unique features, the cart makes testing easy, effective, and efficient. You can test water clarity, flow, temperature, and spread—all at the same time! Most safety shower testing kits create a mess, take too much time to use, and don't fully help you stay in compliance with OSHA & ANSI standards. Transform the way you test emergency showers with Green Gobbler Safety. Read More

  • Kestrel 5400 Heat Stress Tracker WBGT Monitoring for Workplace Safety

    Ensure safety with the Kestrel® 5400 Heat Stress Tracker, the go-to choice for safety professionals and endorsed by the Heat Safety & Performance Coalition. This robust, waterless WBGT meter is ideal for both indoor and outdoor environments, offering advanced monitoring and data logging essential for OSHA compliance. It features pre-programmed ACGIH guidelines and alert settings to quickly signal critical conditions. Integrated with the cloud-based Ambient Weather Network, the 5400 allows managers to view, track, and log job site conditions remotely, ensuring constant awareness of potential hazards. Its capability for real-time mobile alerts and remote data access promotes proactive safety management and workplace protection, solidifying its role as a crucial tool in industrial hygiene. Read More

Featured

Artificial Intelligence