HIPAA Compliance — What Most People Get Wrong and Why Accepting Insurance is a Privilege
The world of HIPAA is a complicated and ever-changing landscape. As qualified technology compliance HIPAA experts (PK Tech owns the Compliancy...
2 min read
Megan Schutz September 1, 2021
Recently, personal data was leaked from over 100,000 patients at HealthReach Community Health Centers in Maine. How did this happen? Simple: by improper disposal of the health center’s hard drives (source).
Let’s dive into this deeper.
The hard drives from the healthcare giant were disposed of by an employee at a third-party data storage location. The breach took place in early April but was not uncovered until a month later when the investigation found that PII (personally identifiable information) and PHI (protected health information) of patients were compromised. Compromised information included names, birth dates, addresses, medical insurance information, social security numbers, medical records, lab results, and treatment records. Despite the leak of sensitive data, the provider noted that no data was misused due to the breach.
As is common practice in the fallout of this type of breach, patients impacted can enroll in complimentary identity theft protection services for one year of monitoring, identify theft recovery services and a one million dollar reimbursement policy. Affected patients were encouraged to do so.
PK Tech has worked in the healthcare space for over ten years. We can help with risk assessments, ongoing services, and more. Reach out to us for a consultation.
The world of HIPAA is a complicated and ever-changing landscape. As qualified technology compliance HIPAA experts (PK Tech owns the Compliancy...
The US Department of Health and Human Services (HHS) recently warned healthcare providers of a new ransomware threat targeting the healthcare sector,...
A $1,040,000 fine for a fairly small provider. That’s the number we’ll be talking about in this blog. Ready to keep reading?