Warby Parker Fined $1,500,000 for HIPAA Noncompliance

The HHS Office for Civil Rights (OCR) has announced its first financial penalty for HIPAA noncompliance under the Trump administration. The data breach that triggered the OCR investigation and the initiation of that investigation both occurred during President Trump’s previous stint as president.

OCR launched an investigation of Warby Parker, a non-prescription eyewear manufacturer and online retailer, after being informed in December 2018 about a credential stuffing incident. Credential stuffing is the term given to an attack where credentials are obtained in a data breach of one platform and are used to try to access the accounts of individuals on an unrelated platform. These attacks are only possible if the same credentials have been used to secure multiple accounts. Customer accounts were compromised between September 25, 2018, and November 30, 2018.

Warby Parker submitted an addendum to the initial breach report to OCR on September 18, 2020, stating that 197,986 individuals had their electronic protected health information (ePHI) compromised in the incident. The data involved included names, addresses, email addresses, the last four digits of any payment card information stored on the customer’s account, and the prescription information of 177,890 individuals.

An investigation was opened by OCR when the initial breach report was received, and OCR notified Warby Parker about the investigation of compliance with the HIPAA Rules on September 16, 2019. Warby Parker suffered further credential stuffing breaches in September 2019, January 2020, April 2020, and June 2022, although those attacks only resulted in unauthorized access to the accounts of 484 individuals.

Credential stuffing attacks are often blamed on the individuals whose accounts are compromised, as they have engaged in poor security practices, reusing the same password on multiple accounts. In this case, OCR identified noncompliance with the HIPAA Rules during the investigation. Specifically, between 2018 and 2024, Warby Parker had not conducted a HIPAA-compliant risk analysis, inasmuch as it was not an accurate and thorough assessment of all potential risks and vulnerabilities to the confidentiality, integrity, and availability of the ePHI.

Between 2018 and 2022, Warby Parker had not implemented sufficient security measures to reduce risks and vulnerabilities to a reasonable and appropriate level, and between 2018 and 2020, Warby Parker had not implemented procedures to regularly review records of information system activity, only complying with this HIPAA requirement from May 12, 2020.

HIPAA
Compliance
Checklist

Simple Guidelines
Immediate PDF Download

Immediate Access

Privacy Policy

Download Free Checklist

Warby Parker was given the opportunity to settle the alleged HIPAA violations informally, but failed to respond. While evidence of mitigating factors was submitted to OCR, they were insufficient to support a waiver of the penalty. Evidence was submitted to support Warby Parker’s claim that recognized security practices had been implemented continuously for the 12 months prior to the data breach; however, OCR found that evidence to be insufficient and did not reduce the financial penalty and implemented a civil monetary penalty of $1,500,000.

“Identifying and addressing potential risks and vulnerabilities to electronic protected health information is necessary for effective cybersecurity and compliance with the HIPAA Security Rule,” said OCR Acting Director Anthony Archeval. “Protecting individuals’ electronic health information means regulated entities need to be vigilant in implementing and complying with the Security Rule requirements before they experience a breach.”

About Liam Johnson

Liam Johnson has produced articles about HIPAA for several years. He has extensive experience in healthcare privacy and security. With a deep understanding of the complex legal and regulatory landscape surrounding patient data protection, Liam has dedicated his career to helping organizations navigate the intricacies of HIPAA compliance. Liam focusses on the challenges faced by healthcare providers, insurance companies, and business associates in complying with HIPAA regulations. Liam has been published in leading healthcare publications, including The HIPAA Journal. Liam was appointed Editor-in-Chief of The HIPAA Guide in 2023. Contact Liam via LinkedIn: https://www.linkedin.com/in/liamhipaa/