Business Associates Can Pay Directly for Breaches
Business associates can be directly liable for a breach of unsecure protected health information (PHI) and could have to pay OCR directly, a top OCR official told HealthLeaders Media at the 18th Annual National HIPAA Summit Wednesday afternoon.
HealthLeaders Media asked Sue McAndrew, deputy director for Health Information Privacy for OCR, if a business associate could end up paying out of its own pocket for a breach.
The answer is yes.
"Business associates going forward will be directly liable for violations that occur in their possession," McAndrew said. "The fines would be imposed upon the BA, and if they can't pay, we send them to jail."
McAndrew laughed at the line about "jail," and said it was in jest.
However, she went on to say OCR would consider waiving—or decreasing—some of the penalties after an assessment of the financial state of a violating hospital. She also said that the "settlement door is always open."
On Wednesday, McAndrews also released breach numbers for the month of January:
- As of January 2010, there have been 35 reports of breaches affecting 500-plus individuals, resulting in 712,000 notices.
- Most of the reports were ePHI contained in lost or stolen unencrypted media or portable device.
- There were more than 300 reports of smaller breaches.
- Most of the paper records were sent to wrong fax numbers, wrong addresses, and wrong individuals.
Dom Nicastro is a senior managing editor at HCPro, Inc. in Marblehead, MA. He edits the Briefings on HIPAA and Health Information Compliance Insider newsletters. E-mail him at dnicastro@hcpro.com.

- Ten Ways to Increase Nurses' Time at the Bedside
- Six Reasons Proposed Hospital Advertising Ban Will Never Pass
- Computer-Controlled Pancreas Could Close the Diabetes Loop
- Medical Breakthroughs That Will Change Healthcare
- Killingsworth Resigns from BCBS of MA
- Hospitals Make Employee Flu Vaccinations a Patient Safety Issue
- Physicians Generate $1.5M Annually for Their Hospitals, Says Survey
- Match Day a Reminder of Primary Care's Struggles
- Hospital Monitors Infectious Diseases Using Real-Time Surveillance
- Massachusetts Investigating Wide Disparities in Hospital, Provider Reimbursements
