Lahey Hospital and Medical Center in Burlington, MA, has agreed to settle potential violations of the Health Insurance Portability and Accountability Act (HIPAA) with the Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Lahey will pay $850,000 and will adopt a “robust” corrective action plan to correct deficiencies in its HIPAA compliance program, OCR reports. Lahey is a nonprofit teaching hospital affiliated with Tufts Medical School.
Lahey notified OCR that a laptop was stolen from an unlocked treatment room during the overnight hours on Aug. 11, 2011. The laptop was on a stand that accompanied a portable CT scanner. It operated the scanner and produced images for viewing through Lahey’s Radiology Information System and Picture Archiving and Communication System. The laptop hard drive contained the protected health information (PHI) of 599 individuals. Evidence obtained through OCR’s subsequent investigation indicated widespread non-compliance with the HIPAA rules, including:
-
failure to conduct a thorough risk analysis of all of its PHI;
-
failure to physically safeguard a workstation that accessed PHI;
-
failure to implement and maintain policies and procedures regarding the safeguarding of PHI maintained on workstations used with diagnostic/laboratory equipment;
-
lack of a unique user name for identifying and tracking user identity with respect to the workstation at issue in this incident;
-
failure to implement procedures that recorded and examined activity in the workstation at issue in this incident;
-
impermissible disclosure of 599 individuals’ PHI.
Lahey also must address its history of non-compliance with the HIPAA rules by providing OCR with a comprehensive, enterprisewide risk analysis and corresponding risk management plan, as well as reporting certain events and providing evidence of compliance.
The Resolution Agreement and Corrective Action Plan can be found on the OCR website at http://tinyurl.com/gl5ysge.