HHS recently entered into a $3.5 million settlement agreement with a health care provider (the ?ãProvider?ÃÂ¥) on behalf of five entities under its common ownership and control for violations of the HIPAA privacy and security rules. Each of the five entities constituted a ?ãcovered entity?ÃÂ¥ under HIPAA. In 2013, the Provider filed five breach reports with HHS, each of which pertained to a separate incident that implicated the ?ãelectronic protected health information?ÃÂ¥ (?ãEPHI") of one of those covered entities. HHS?ÃÃs subsequent investigation of the breaches revealed a number of violations of the HIPAA privacy and security rules, including that certain of the covered entities:
- Failed to conduct an accurate and thorough risk analysis of potential risks and vulnerabilities to the confidentiality, integrity, and availability of EPHI;
- Provided unauthorized access to EPHI for a purpose not permitted by the HIPAA privacy rules;
- Failed to implement policies and procedures to address security incidents; and
- Failed to implement a mechanism to encrypt and decrypt EPHI when it was reasonable and appropriate to do so under the circumstances.