Unencrypted laptop costs healthcare system $1M+ in fines

The largest health system in the smallest state has agreed to pay $1,040,000 to HHS’s Office for Civil Rights (OCR).

The settlement requires five-hospital Lifespan Health Services to pay the amount and take corrective actions for failing to meet HIPAA rules on data encryption.

The potential for a significant breach was discovered after the health system reported an employee’s laptop had been stolen.

With the filched portable computer in unknown hands, more than 20,000 patients are at risk of theft involving their unencrypted names, medical record numbers, demographic information and medication lists, according to a July 27 announcement from HHS.

In the announcement, OCR director Roger Severino points out that laptops, smartphones and tablet computers go missing every day.

“[T]hat’s the hard reality,” he adds. “Covered entities can best protect their patients’ data by encrypting mobile devices to thwart identity thieves.”   

Lifespan’s member hospitals include 719-bed Rhode Island Hospital in Providence and its adjacent pediatric facility, Hasbro Children’s Hospital.

According to coverage by GovInfoSecurity, the Lifespan settlement is OCR’s third such deal this year and by far the largest. At the same time, the office is behind the pace it set last year, when it announced 13 HIPAA enforcement actions totaling about $15.3 million. Among these was a $3 million settlement with the University of Rochester Medical Center in upstate New York.

Dave Pearson

Dave P. has worked in journalism, marketing and public relations for more than 30 years, frequently concentrating on hospitals, healthcare technology and Catholic communications. He has also specialized in fundraising communications, ghostwriting for CEOs of local, national and global charities, nonprofits and foundations.

Around the web

The tirzepatide shortage that first began in 2022 has been resolved. Drug companies distributing compounded versions of the popular drug now have two to three more months to distribute their remaining supply.

The 24 members of the House Task Force on AI—12 reps from each party—have posted a 253-page report detailing their bipartisan vision for encouraging innovation while minimizing risks. 

Merck sent Hansoh Pharma, a Chinese biopharmaceutical company, an upfront payment of $112 million to license a new investigational GLP-1 receptor agonist. There could be many more payments to come if certain milestones are met.