Health Fitness Corporation Settles Alleged HIPAA Risk Analysis Violation for $228,000
The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) is continuing with its risk analysis enforcement initiative. OCR has announced another financial penalty to resolve an alleged violation of this foundational HIPAA Security Rule implementation specification. This is the fifth penalty to be announced by OCR since the risk analysis compliance initiative was launched.
The Illinois-based business associate Health Fitness Corporation has agreed to settle the alleged HIPAA violation with no admission of liability or wrongdoing. Under the terms of the settlement, Health Fitness Corporation will pay a $227,816 financial penalty and will adopt a corrective action plan to ensure further compliance. Health Fitness Corporation provides wellness plans to clients across the country. Between October 15, 2018, and January 25, 2019, OCR received multiple breach reports from Health Fitness Corporation on behalf of its covered entity clients. Across those incidents, the electronic protected health information of up to 4,304 individuals was exposed due to a server misconfiguration. The misconfiguration allowed unauthorized access to patient data, and files and folders were indexed by search engines. The server misconfiguration occurred in August 2015 and was identified and fixed in June 2018.
The administrative safeguards of the HIPAA Security Rule include the requirement to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information – 45 C.F.R. § 164.308(a)(1)(ii)(A). OCR’s investigation determined that the first HIPAA-compliant risk analysis conducted by the company was on January 19, 2024.
OCR notified Health Fitness Corporation about its intention to impose a financial penalty and offered the opportunity to settle the matter informally. If a regulated entity chooses not to settle and is unsuccessful in its attempt to get the financial penalty waived, the fine imposed will be substantially higher; however, when a civil monetary penalty is imposed, OCR cannot force the regulated entity to implement a corrective action plan.
In this case, a settlement was agreed that involves a reduced financial penalty, a corrective action plan, and 2 years of monitoring by OCR. The corrective action plan includes the requirement to conduct an annual review and update of its risk analysis; develop, implement, and maintain policies and procedures for evaluating environmental and operational changes; and conduct a risk analysis promptly after any environmental and operational changes that impact electronic protected health information or the systems on which the information is stored.