Pennsylvania Health System Hit with $950K Fine for Non-Compliance with the HIPAA Security Rule

A Pennsylvania health system has been fined $950,000 by the HHS’ Office for Civil Rights as part of a settlement to resolve alleged violations of the HIPAA Security Rule that were uncovered during the investigation of a ransomware attack. In addition to the financial penalty, Heritage Health System is required to implement a corrective action plan to ensure full compliance with the HIPAA Rules and will be monitored for compliance by OCR for 3 years.

Heritage Health System, which provides care at three hospitals and dozens of healthcare facilities in Pennsylvania, Ohio, and West Virginia, fell victim to a ransomware attack in 2017. OCR launched an investigation in response to media reports about a security breach, rather than a breach report from Heritage Health System. The OCR breach portal does not list any ransomware or hacking incident at Heritage Health in 2017, which indicates the breach did not involve the protected health information of 500 or more individuals.

Ransomware attacks on healthcare organizations have increased sharply in recent years and many ransomware-as-a-service groups are actively targeting the sector. According to OCR data, ransomware-related data breaches have increased by 264% since 2018.

OCR Director Melanie Fontes Rainer has publicly stated that ransomware attacks and hacking incidents are an enforcement priority, and the department is looking closely at ransomware and hacking-related data breaches to determine whether the breached entities are complying with the HIPAA Security Rule. This is the third financial penalty to be imposed on a HIPAA-regulated entity over a ransomware attack. The previous two financial penalties were both imposed on healthcare providers that experienced ransomware attacks in 2019.

The financial penalty was not imposed for suffering a ransomware attack, as OCR appreciates that even full compliance with the HIPAA Security Rule may not be enough to prevent successful attacks; however, during the investigation, OCR identified non-compliance with multiple provisions of the HIPAA Security Rule, which indicated that Heritage Health System was not prepared for an attack, despite a high risk of being targeted.

OCR determined that Heritage Health System had not conducted a comprehensive and accurate risk analysis to identify risks and vulnerabilities to electronic protected health information (ePHI), there was no contingency plan for incidents that prevent access to systems containing ePHI, and there was a lack of technical policies and procedures for limiting access to systems containing ePHI to authorized individuals and software solutions.

HIPAA
Compliance
Checklist

Simple Guidelines
Immediate PDF Download

Immediate Access

Privacy Policy

Download Free Checklist

“Hacking and ransomware are the most common type of cyberattacks within the health care sector. Failure to implement the HIPAA Security Rule requirements leaves health care entities vulnerable and makes them attractive targets to cyber criminals,” said OCR Director Melanie Fontes Rainer in the settlement announcement. “Safeguarding patient protected health information protects privacy and ensures continuity of care, which is our top priority. We remind and urge health care entities to protect their records systems and patients from cyberattacks.”

Fontes Rainer also reminded HIPAA-regulated entities of their responsibilities under the HIPAA Security Rule, and how Security Rule compliance can reduce the risk of a successful attack and limit the impact of a successful attack.

About Liam Johnson

Liam Johnson has produced articles about HIPAA for several years. He has extensive experience in healthcare privacy and security. With a deep understanding of the complex legal and regulatory landscape surrounding patient data protection, Liam has dedicated his career to helping organizations navigate the intricacies of HIPAA compliance. Liam focusses on the challenges faced by healthcare providers, insurance companies, and business associates in complying with HIPAA regulations. Liam has been published in leading healthcare publications, including The HIPAA Journal. Liam was appointed Editor-in-Chief of The HIPAA Guide in 2023. Contact Liam via LinkedIn: https://www.linkedin.com/in/liamhipaa/