HIPAA Security Officer Aces OCR Investigations
Cignet Health's failure to cooperate with the government's HIPAA privacy and security enforcer just cost the Maryland hospital system $3 million.
It cost the system another $1.3 million when it failed to provide patients copies of medical records within 30 (and no later than 60) days.
The message can't be any clearer: when the Office for Civil Rights (OCR) knocks, answer the door.
About 48 hours after the Cignet news broke, OCR announced a $1 million settlement against Massachusetts General Hospital in Boston for an incident involving the loss of 192 patient records belonging to Mass General's Infectious Disease Associates outpatient practice, including patients with HIV/AIDS.
One security officer who "got it" before Cignet's landmark fine and settlement were announced is Greg Young.
Young, the information security officer at Mammoth Hospital in Mammoth Lakes, CA, has worked with OCR on about a handful of investigations.
"I never had the sense they were going to let me get away with anything," Young says. "They were pretty demanding and yet always professional. At one point they reminded me that they have the last word. Though I thought I was cooperating, they wanted more details. I'm amazed that Cignet got away with as much as they did for as long as they did."
- Few Winners Among MSSP Participants
- Technology Lights Up Health Innovation Forum
- NCQA Releases Annual Health Plan Rankings
- How much does that x-ray cost? You can find out in NH
- Data Points to Boom in Private HIX
- When a hospital closes
- Anthem Blue Cross, 7 CA Health Systems Create New Challenger, Business Model
- Administration: 7.3M now enrolled in Obamacare
- US health system among least efficient before Obamacare
- EHR Systems 'Immature, Costly,' AMA Says