OCR Settles Alleged HIPAA Violations with USR Holdings for $337,750

The HHS’ Office for Civil Rights has announced a $337,750 settlement with the Florida business associate USR Holdings to resolve alleged violations of the HIPAA Security Rule. OCR launched an investigation of USR Holdings after receiving a breach report on February 8, 2019, that involved the electronic protected health information (ePHI) of 2,903 individuals. The notification covered protected health information from three of its covered entity clients. USR Holdings discovered that between December 8, 2018, and January 9, 2019, an unauthorized third party accessed a database and deleted ePHI.

OCR determined that there had been an impermissible disclosure of the ePHI of 2,903 individuals and multiple violations of the HIPAA Security Rule. USR Holdings had not conducted a comprehensive and accurate risk analysis to identify risks and vulnerabilities to the confidentiality, integrity, and availability of the ePHI it holds. The Security Rule requires HIPAA-regulated entities to regularly review records of activity in information systems, such as audit logs, access reports, and security incident tracking reports. USR Holdings lacked policies and procedures for reviewing those records. USR Holdings had also failed to establish procedures for creating and maintaining exact retrievable copies of ePHI, which meant that ePHI was permanently lost.

USR Holdings opted to settle the alleged HIPAA violations with no admission of liability or wrongdoing and paid a $337,750 financial penalty. The settlement agreement also includes a corrective action plan (CAP). The CAP requires USR Holdings to conduct a comprehensive and accurate risk analysis, develop a risk management plan to address and mitigate any risks and vulnerabilities identified by the risk analysis, and develop a process for evaluating environmental and operational changes that affect the security of ePHI.

Policies and procedures must also be developed, implemented, and revised as necessary to ensure compliance with the HIPAA Rules, and those policies and procedures must be shared with members of the workforce.

About Liam Johnson

Liam Johnson has produced articles about HIPAA for several years. He has extensive experience in healthcare privacy and security. With a deep understanding of the complex legal and regulatory landscape surrounding patient data protection, Liam has dedicated his career to helping organizations navigate the intricacies of HIPAA compliance. Liam focusses on the challenges faced by healthcare providers, insurance companies, and business associates in complying with HIPAA regulations. Liam has been published in leading healthcare publications, including The HIPAA Journal. Liam was appointed Editor-in-Chief of The HIPAA Guide in 2023. Contact Liam via LinkedIn: https://www.linkedin.com/in/liamhipaa/