OCR Settles With Medical Center for HIPAA Violation

The U.S. Department of Health and Human Services Office for Civil Rights (OCR) has reached a settlement with Saint Joseph’s Medical Center located in Yonkers, New York. This settlement is in response to a violation of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy Rule. The breach involved the unauthorized release of early COVID-19 patients’ protected health information (PHI) to a national media outlet. The OCR’s investigation into Saint Joseph’s Medical Center began after an article by the Associated Press, published on April 28, 2020, included photographs and detailed information about the facility’s patients. This exposure of sensitive patient information, including COVID-19 diagnoses, medical statuses, prognoses, vital signs, and treatment plans, constituted a clear violation of national patient-privacy-protection laws.

The settlement shows the importance of adhering to patient privacy laws, especially during public health emergencies like the COVID-19 pandemic. OCR Director Melanie Fontes Rainer emphasized that patients should not have to worry about their health information being disclosed to the media without their authorization. The HIPAA Privacy Rule strictly prohibits regulated entities, including healthcare providers, from disclosing PHI to the media without first obtaining written authorization from the patient. This rule applies irrespective of the presence of print or television reporters on healthcare premises. Saint Joseph’s Medical Center failed to adhere to these privacy standards, leading to the unauthorized dissemination of patient information.

As part of the settlement, Saint Joseph’s Medical Center is required to pay $80,000 to the OCR and implement a comprehensive corrective action plan. This plan outlines the development of written policies and procedures that comply with the HIPAA Privacy Rule. The medical center has agreed to conduct extensive training for its workforce on these revised policies and procedures. The OCR will monitor the implementation of these measures at Saint Joseph’s Medical Center for two years, ensuring that the facility adheres to the stipulated privacy standards and the corrective action plan.

OCR settlements with healthcare providers and other entities can result in significant financial penalties for breaches of PHI and violations of patient rights. The healthcare industry has seen a notable rise in penalization for HIPAA violations, in part due to escalating cybersecurity threats and the quick development of patient information management. Criminal charges can also be imposed for intentional HIPAA violations, including unauthorized access to electronic health records or sharing patient information without consent.

Tags

Daniel Lopez

Daniel Lopez

Daniel Lopez stands out as an exceptional HIPAA trainer, dedicated to elevating standards in healthcare data protection and privacy. Daniel, recognized as a leading authority on HIPAA compliance, serves as the HIPAA specialist for Healthcare IT Journal. He consistently offers insightful and in-depth perspectives on a wide range of HIPAA-related topics, addressing both typical and complex compliance issues. With his extensive experience, Daniel has made significant contributions to multiple publications such as hipaacoach.com, ComplianceJunction, and The HIPAA Guide, enriching the field with his deep knowledge and practical advice in HIPAA regulations. Daniel offers a comprehensive training program that covers all facets of HIPAA compliance, including privacy, security, and breach notification rules. Daniel's educational background includes a degree in Health Information Management and certifications in data privacy and security. You can contact Daniel via HIPAAcoach.com.

Get The FREE HIPAA Checklist

Discover everything you need to become HIPAA compliant
Scroll to Top

Get the free newsletter

Discover everything you need to become HIPAA compliant
Please enable JavaScript in your browser to complete this form.
Name

Get The FREE HIPAA Checklist

Discover everything you need to become HIPAA compliant
Please enable JavaScript in your browser to complete this form.
Name