Accountancy Firm Pays $175,000 Penalty for HIPAA Violation
The New York accountancy and management consultancy firm BST & Co. CPAs, LLP, has agreed to a $175,000 settlement with the HHS’ Office for Civil Rights to resolve an alleged violation of the HIPAA Security Rule. The enforcement action is the tenth under OCR’s HIPAA enforcement initiative targeting noncompliance with the risk analysis requirement of the HIPAA Security Rule, and its fifteenth investigation of a ransomware attack to result in a financial penalty.
The enforcement initiative targets the most commonly identified HIPAA Security Rule violation. All HIPAA-regulated entities – healthcare providers, health plans, healthcare clearinghouses, and business associates – are required to conduct an accurate, organization-wide risk analysis to identify all risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information (ePHI). All identified risks must then be subject to a risk management process and be reduced to a reasonable and appropriate level. If the risk analysis is not completed or is not comprehensive, risks are likely to be missed and will not be appropriately managed.
Through its HIPAA compliance audits and data breach investigations, this Security Rule violation is frequently identified, more so than any other HIPAA Security Rule provision. Compliance with this HIPAA requirement will go a long way to improving an organization’s security posture and making it harder for malicious actors to access ePHI. OCR currently has a large backlog of data breach investigations, and by looking specifically at this requirement, OCR will be able to clear the backlog more quickly.
The investigation of BST & Co. CPAs was initiated after OCR received a breach report on February 16, 2020, about a ransomware attack involving the ePHI of 170,000 individuals. The Maze ransomware group gained a foothold in the network via a phishing attack and had access to files containing ePHI from December 4, 2019, to December 7, 2019. The attack was detected by BST & Co. CPAs on December 7, 2019, when ransomware was used to encrypt files. BST & Co. CPAs investigated the attack and determined that ePHI was exposed, including names, dates of birth, billing codes, medical record numbers, and insurance descriptions related to patients of its healthcare clients.
OCR notified BST & Co. CPAs of its intention to impose a financial penalty to resolve the risk analysis violation, and BST & Co. CPAs was given the opportunity to settle the case informally. If that option is refused, OCR moves to impose a civil monetary penalty, which is greater than any settlement figure. In order to settle, a financial penalty must be paid, and the regulated entity must agree to adopt a corrective action plan.
The BST & Co. CPAs corrective action plan requires a comprehensive risk analysis, a risk management plan to reduce risks and vulnerabilities, revisions of HIPAA policies and procedures, distribution of those policies and procedures to the workforce, workforce training on those policies and procedures, and updates to its security awareness training program. BST & Co. CPAs will be monitoried for compliance with the corrective action plan for two years.
“A HIPAA risk analysis is essential for identifying where ePHI is stored and what security measures are needed to protect it,” OCR Director Paula M. Stannard said in OCR’s announcement about the HIPAA penalty. “Completing an accurate and thorough risk analysis that informs a risk management plan is a foundational step to mitigate or prevent cyberattacks and breaches.”
