Guam Hospital Authority Pays $25K Penalty to Resolve HIPAA Risk Analysis Violation

The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has resolved another investigation of a ransomware attack with a financial penalty. Guam Memorial Hospital Authority (GMHA) was determined to have failed to conduct a comprehensive and accurate risk analysis to identify all risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information (ePHI).

Guam Memorial Hospital Authority (GMHA) is a public hospital in the U.S. Territory of Guam. On January 7, 2019, a complaint was received by OCR about a ransomware attack on Guam Memorial Hospital in December 2018 that involved unauthorized access to the ePHI of up to 5,000 individuals. While investigating the complaint and data breach, GMHA received another complaint about alleged HIPAA violations. Two former employees had accessed its network and patients’ ePHI after their employment had ended.

OCR determined that GMHA had failed to conduct a HIPAA-compliant risk analysis and informed GMHA about the alleged HIPAA violation and the intention to impose a financial penalty. GMHA was given the opportunity to settle the alleged violation informally, and a $25,000 settlement was negotiated to resolve alleged HIPAA violations. In addition, GMHA agreed to implement a corrective action plan (CAP) to ensure future compliance with the HIPAA Rules.

The CAP requires GMHA to conduct a comprehensive and accurate risk analysis; develop and implement a risk management plan to reduce any identified risks and vulnerabilities to a low and acceptable level; implement a process for reviewing logs of activity in information systems containing ePHI; develop, revise, and maintain policies and procedures to achieve compliance with the HIPAA Rules; distribute those policies to the workforce; augment its HIPAA and Security awareness training programs; review all access credentials and terminate access, credentials, accounts, and privileges to prevent unauthorized access to ePHI. GMHA must also conduct breach risk assessments of the two breaches and report them to OCR and issue notification letters to the affected individuals. Neither incident is currently shown on the OCR breach portal, which suggests they were never reported to OCR as data breaches. OCR will monitor GMHA for compliance with the CAP for a period of 3 years from the date of the resolution agreement.

This is OCR’s 11th ransomware attack investigation to result in a financial penalty and the 7th financial penalty imposed under OCR’s risk analysis enforcement initiative. So far this year, 13 HIPAA enforcement actions have resulted in financial penalties, with $6,505,566 paid in settlements and civil monetary penalties.

“Ransomware and hacking are the primary cyber-threats to electronic protected health information within the health care industry. Failure to conduct a HIPAA risk analysis puts this information at risk and vulnerable to future ransomware attacks and other cyber-threats,” said OCR Acting Director Anthony Archeval.

HIPAA
Compliance
Checklist

Simple Guidelines
Immediate PDF Download

Immediate Access

Privacy Policy

Download Free Checklist

About Liam Johnson

Liam Johnson has produced articles about HIPAA for several years. He has extensive experience in healthcare privacy and security. With a deep understanding of the complex legal and regulatory landscape surrounding patient data protection, Liam has dedicated his career to helping organizations navigate the intricacies of HIPAA compliance. Liam focusses on the challenges faced by healthcare providers, insurance companies, and business associates in complying with HIPAA regulations. Liam has been published in leading healthcare publications, including The HIPAA Journal. Liam was appointed Editor-in-Chief of The HIPAA Guide in 2023. Contact Liam via LinkedIn: https://www.linkedin.com/in/liamhipaa/