Ambry Genetics Settles OCR HIPAA Investigation for $700,000
The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has announced another settlement to resolve alleged violations of the HIPAA Rules. Ambry Genetics Corporation was determined to have violated three provisions of the HIPAA Rules and will pay a $700,000 financial penalty to resolve the alleged violations.
Ambry Genetics, a California-based genetic testing and clinical genomics company, experienced a security incident that resulted in unauthorized access to an employee’s email account between January 22 and January 24, 2020. An employee responded to a phishing email and disclosed their credentials. The credentials provided access to an account that contained the electronic protected health information of 225,370 individuals, including names, contact information, dates of birth, medical information, driver’s license numbers, and Social Security numbers.
The breach was identified by Ambry Genetics on January 22, 2020, and was reported to OCR on March 22, 2020. OCR launched an investigation to determine if the breach occurred as a result of a failure to comply with the HIPAA Rules and identified violations of three provisions of the HIPAA Rules.
HIPAA-regulated entities must conduct a risk analysis to identify all risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI. The risk analyses must be comprehensive and cover all locations where ePHI is created, maintained, processed, stored, or transmitted, and all systems that touch ePHI. OCR determined that a HIPAA-compliant risk analysis has not been completed, in violation of the risk analysis implementation specification – 45 C.F.R. § 164.308(a)(1)(ii)(A) – of the HIPAA Security Rule.
The HIPAA Security Rule also requires HIPAA-regulated entities to implement policies and procedures for terminating access to ePHI when access is no longer required, such as when an employee is terminated or otherwise leaves the company, or when roles and responsibilities change and access to ePHI is no longer required. OCR determined that policies and procedures related to this Security Rule implementation specification – 45 C.F.R. § 164.308(a)(3)(ii)(C) – had not been implemented.
The HIPAA Security Rule also requires access controls to be implemented. A unique username must be assigned to each individual who requires access to ePHI or systems containing ePHI to allow their identity to be determined and their activities to be tracked. OCR determined that Ambry Genetics failed to comply with this implementation specification – 45 C.F.R. § 164.312(a)(2)(i) – as unique usernames had not been assigned to all individuals.
OCR determined that the HIPAA violations warranted a financial penalty. Ambry Genetics agreed to settle the alleged violations and pay a $700,000 financial penalty. The settlement also includes a corrective action plan to address the areas of noncompliance identified by OCR, and Ambry Genetics will be monitored by OCR for 2 years to ensure compliance.
OCR has imposed ten financial penalties this year to resolve alleged violations of the HIPAA Rules and has collected more than $3 million in financial penalties. OCR has two main areas of focus under current enforcement initiatives – the risk analysis implementation specification of the Security Rule and the HIPAA Privacy Rule Right of Access.
All ten penalties this year have involved violations of either of those provisions, although any HIPAA violation can attract a financial penalty. OCR has stated that the risk analysis enforcement initiative has now been expanded to include risk management. Risks must be identified, but OCR will also need to be shown that the identified risks have been reduced to an acceptable level, in a reasonable timeframe.
