HIPAA Security Officer Aces OCR Investigations
Cignet Health's failure to cooperate with the government's HIPAA privacy and security enforcer just cost the Maryland hospital system $3 million.
It cost the system another $1.3 million when it failed to provide patients copies of medical records within 30 (and no later than 60) days.
The message can't be any clearer: when the Office for Civil Rights (OCR) knocks, answer the door.
About 48 hours after the Cignet news broke, OCR announced a $1 million settlement against Massachusetts General Hospital in Boston for an incident involving the loss of 192 patient records belonging to Mass General's Infectious Disease Associates outpatient practice, including patients with HIV/AIDS.
One security officer who "got it" before Cignet's landmark fine and settlement were announced is Greg Young.
Young, the information security officer at Mammoth Hospital in Mammoth Lakes, CA, has worked with OCR on about a handful of investigations.
"I never had the sense they were going to let me get away with anything," Young says. "They were pretty demanding and yet always professional. At one point they reminded me that they have the last word. Though I thought I was cooperating, they wanted more details. I'm amazed that Cignet got away with as much as they did for as long as they did."
- ICD-10 Delay Alters Provider, Vendor Prep
- Providers Lag as Consumers Set Agenda
- Payment Reform Naysayers 'Better Wake Up'
- As Hospitalist Patient Loads Rise, So Do Hospital Costs
- HIT Leaders Want Flexibility, Transparency from Next HHS Chief
- Crisis Spurs Healthcare Payment Reform in Arkansas
- Esther Dyson Launches Population Health Challenge
- Reduce Readmissions by Activating Patients to Do 'Self-Care'
- Advance Directives: Let's Make a Law
- Hire Care Coordinators Strategically