OCR Announces HIPAA Settlement for Careless Handling of HIV Information.
The Department of Health and Human Services (HHS) Office for Civil Rights (OCR) recently reported that St. Lukeโs-Roosevelt Hospital Center Inc. (St. Lukeโs) paid $387,200 as part of a Health Insurance Portability and Accountability Act (HIPAA) settlement. St. Lukeโs also agreed to implement a comprehensive corrective action plan (CAP) to settle the HIPAA Privacy Rule violations. St. Lukeโs provides comprehensive health services to persons living with HIV or AIDS and other chronic diseases. The compliance review was initiated when OCR responded to a complaint alleging that a St. Lukeโs staff member made an impermissible disclosure of a patientโs protected health information (PHI) to the complainantโs employer. The alleged disclosure included sensitive information concerning HIV status, medical care, sexually transmitted diseases, medications, sexual orientation, mental health diagnosis, and physical abuse. OCR found that St. Lukeโs staff impermissibly faxed the patientโs PHI to his employer rather than sending it to the requested personal post office box. OCR also found another related breach that occurred nine months earlier; however, St. Lukes had not addressed the vulnerabilities in their compliance program, since then, to prevent impermissible disclosures.
The full article is available at:
https://www.hhs.gov/about/news/2017/05/23/careless-handling-hiv-information-costs-entity.html