NY Surgery Center Pays Penalty for Risk Analysis and Breach Notification Failures

Syracuse ASC (Specialty Surgery Center of Central New York) has agreed to pay a $250,000 fine and adopt a corrective action plan to resolve alleged violations of the HIPAA Security and Breach Notification Rules. Syracuse ASC is an ambulatory surgery center in Liverpool, New York. Like many healthcare providers, Syracuse ASC was targeted by a ransomware group, which had access to its network from March 14, 2021, through March 31, 2021. The attack was discovered when PYSA ransomware was used to encrypt files. The ransomware actor had access to the protected health information of 24,891 patients, including names, dates of birth, Social Security numbers, financial information, and clinical treatment information.

It is not always possible to prevent unauthorized access to computer networks, even when reasonable and appropriate security measures are implemented. It is, however, important to assess potential risks and vulnerabilities to electronic protected health information (ePHI) and manage those risks and reduce them to an acceptable level. When OCR investigates data breaches, OCR will need to be provided with documentation that demonstrates that a comprehensive and accurate risk analysis has been conducted, and that any identified risks and vulnerabilities have been reduced to a reasonable level. OCR investigated Syracuse ASC and determined that a risk analysis had never been conducted, in violation of one of the foundational provisions of the HIPAA Security Rule.

OCR also determined that timely breach notifications had not been issued. The ransomware attack was detected on March 31, 2021, yet the Secretary of the HHS and the individuals whose protected health information was exposed were not notified about the data breach until October 14, 2021, more than six months after the ransomware attack was detected. The HIPAA Breach Notification Rule requires notifications to be issued to the HHS Secretary, affected individuals, and media within 60 days of the discovery of a data breach.

OCR agreed to settle the alleged Security Rule and Breach Notification Rule violations with Syracuse ASC. In addition to the financial penalty, Syracuse ASC is required to:

  • Conduct a comprehensive and accurate risk analysis
  • Develop a risk management plan to reduce potential risks and vulnerabilities to ePHI to a low and acceptable level
  • Develop HIPAA policies and procedures, which at a minimum must include risk analyses, risk management, information system activity reviews, data backups, and breach notifications to the HHS Secretary, media, and affected individuals.
  • Distribute policies and procedures to the workforce and provide training at least annually on those policies and procedures.

“Conducting a thorough HIPAA-compliant risk analysis (and developing and implementing risk management measures to address any identified risks and vulnerabilities) is even more necessary as sophisticated cyberattacks increase,” said OCR Director Paula M. Stannard. “HIPAA-covered entities and business associates make themselves soft targets for cyberattacks if they fail to implement the HIPAA Security Rule requirements.”

This is the 18th financial penalty to be imposed by OCR this year to resolve alleged violations of the HIPAA Rules. OCR is continuing to focus on the risk analysis provision of the HIPAA Security Rule, as it is so important for security. Risk analysis violations were identified in 15 of the 18 cases that resulted in a financial penalty this year. HIPAA-regulated entities should note that three of the enforcement actions this year have included penalties to resolve HIPAA Breach Notification Rule violations. HIPAA-regulated entities must ensure that timely notifications are issued if protected health information is exposed or impermissibly disclosed.

HIPAA
Compliance
Checklist

Simple Guidelines
Immediate PDF Download

Immediate Access

Privacy Policy

Download Free Checklist

About Liam Johnson

Liam Johnson has produced articles about HIPAA for several years. He has extensive experience in healthcare privacy and security. With a deep understanding of the complex legal and regulatory landscape surrounding patient data protection, Liam has dedicated his career to helping organizations navigate the intricacies of HIPAA compliance. Liam focusses on the challenges faced by healthcare providers, insurance companies, and business associates in complying with HIPAA regulations. Liam has been published in leading healthcare publications, including The HIPAA Journal. Liam was appointed Editor-in-Chief of The HIPAA Guide in 2023. Contact Liam via LinkedIn: https://www.linkedin.com/in/liamhipaa/