BayCare Health System Settles Alleged HIPAA Violations for $800,000

BayCare Health System in Florida has settled three alleged violations of the HIPAA Rules with the HHS’ Office for Civil Rights for $800,000. The alleged HIPAA violations were identified by OCR during the investigation of an October 2018 complaint from a patient of BayCare Health St. Joseph’s Hospital in Tampa, Florida.

After the patient visited the hospital, she was contacted by an unknown individual who claimed to have photographs of her printed medical records and was sent a video of her electronic medical records being accessed and scrolled through on a computer screen. OCR investigated the complaint and confirmed unauthorized access to her medical records by a malicious insider. The login credentials used to access those records were for a former non-clinical staff member at a physician’s practice. Access to the medical records had been provided for the purpose of continuity of care.

OCR determined that BayHealth had failed to implement policies and procedures for authorizing access to patients’ electronic medical records, including a failure to limit access to protected health information to the minimum necessary information to allow the required work duties to be performed, as required by the HIPAA Privacy Rule. Under the HIPAA administrative safeguards, regulated entities are required to reduce risks and vulnerabilities to protected health information to a reasonable and appropriate level. OCR determined that BayHealth was not fully compliant with this requirement, and BayHealth had not implemented policies and procedures for regularly reviewing records of information system activity.

BayHealth chose not to contest the findings of the investigation and agreed to a settlement that includes a $800,000 financial penalty, a corrective action plan, and monitoring for compliance with the corrective action plan for 2 years. The corrective action plan requires BayHealth to conduct a comprehensive and accurate risk analysis to identify all risks and vulnerabilities to protected health information and develop and implement a risk management plan to reduce those risks and vulnerabilities to a low and acceptable level.  Policies and procedures must be updated to ensure compliance with the HIPAA Rules, and those policies must be distributed to members of the workforce who have contact with protected health information. BayHealth must also provide training to the workforce on the revised policies and procedures.

Should BayHealth identify a failure by an employee to comply with its policies and procedures and sanctions the employee for the violation, OCR must be notified. BayHealth is also required to provide OCR with implementation reports and annual reports on HIPAA compliance. This is the OCR’s ninth HIPAA enforcement action under the new Trump administration, and the 15th HIPAA penalty to be announced this year. So far in 2025, OCR has collected $7,310,566 in penalties to resolve HIPAA violations.

“In an era of hacking and ransomware attacks, HIPAA-regulated entities still need to ensure that workforce members and other users with access to an electronic medical record only have access to the health information necessary for them to perform their jobs,” said OCR Acting Director Anthony Archeval. “Allowing unrestricted access to patient health information can create an attractive target for a malicious insider.”

HIPAA
Compliance
Checklist

Simple Guidelines
Immediate PDF Download

Immediate Access

Privacy Policy

Download Free Checklist

About Liam Johnson

Liam Johnson has produced articles about HIPAA for several years. He has extensive experience in healthcare privacy and security. With a deep understanding of the complex legal and regulatory landscape surrounding patient data protection, Liam has dedicated his career to helping organizations navigate the intricacies of HIPAA compliance. Liam focusses on the challenges faced by healthcare providers, insurance companies, and business associates in complying with HIPAA regulations. Liam has been published in leading healthcare publications, including The HIPAA Journal. Liam was appointed Editor-in-Chief of The HIPAA Guide in 2023. Contact Liam via LinkedIn: https://www.linkedin.com/in/liamhipaa/