South Shore Hospital's security mistake results in $750K settlement

OOPS - 42.86 Kb
South Shore Hospital in Boston has agreed to pay $750,000 to resolve allegations because the provider failed to protect the personal and confidential health information of more than 800,000 consumers, Massachusetts Attorney General Martha Coakley announced. The investigation and settlement resulted from a data breach reported to the AG’s office in July 2010 that included individual’s names, Social Security numbers, financial account numbers and medical diagnoses.

In February 2010, South Shore shipped three boxes containing 473 unencrypted back-up computer tapes with 800,000 individuals’ personal information and protected health information off-site to be erased. The hospital contracted with Archive Data Solutions to erase the back-up tapes and resell them, according to a release from the state attorney general.

The hospital did not inform Archive Data, the office added, that personal information and protected health information was on the back-up computer tapes nor did South Shore Hospital determine whether Archive Data had sufficient safeguards in place to protect this sensitive information.

South Shore learned only one of the boxes arrived at its destination in Texas in June 2010. The missing boxes have not been recovered although there have been no reports of unauthorized use of the personal information or protected health information of affected individuals to date, the release noted.

The consent judgment approved in Suffolk Superior Court includes a $250,000 civil penalty and a payment of $225,000 for an education fund to be used by the attorney general’s office to promote education concerning the protection of personal information and protected health information. In addition to these payments, the consent judgment credits South Shore Hospital for $275,000 to reflect security measures it has taken subsequent to the breach.

According to the consent judgment, South Shore Hospital also has agreed to take a variety of steps to ensure compliance with state and federal data security laws and regulations, including requirements regarding its contracts with business associates and third-party service providers engaged for data destruction purposes.

The hospital also agreed to undergo a review and audit of certain security measures and to report the results and any corrective actions to the attorney general.

Around the web

The tirzepatide shortage that first began in 2022 has been resolved. Drug companies distributing compounded versions of the popular drug now have two to three more months to distribute their remaining supply.

The 24 members of the House Task Force on AI—12 reps from each party—have posted a 253-page report detailing their bipartisan vision for encouraging innovation while minimizing risks. 

Merck sent Hansoh Pharma, a Chinese biopharmaceutical company, an upfront payment of $112 million to license a new investigational GLP-1 receptor agonist. There could be many more payments to come if certain milestones are met.