Health Net Fined $55K for Data Breach
The complaint filed January 14 says Health Net's six-month delay in notifying Vermont residents violates the Security Breach Notice Act. That law requires data collectors to notify affected individuals of security breaches "in the most expedient time possible and without unreasonable delay."
Health Net violated HIPAA by failing to secure PHI and breached the Consumer Fraud Act by misrepresenting the risk posed to affected individuals in the company's notice letters.
The complaint and proposed consent decree were filed in the U.S. District Court for the District of Vermont. The consent decree must be approved by a judge before it takes effect.
"Health Net has taken significant steps to assure that our members are protected," Health Net says. "We have offered two years of free credit monitoring services for all impacted members who elect this service. This service also includes $1 million of identity theft insurance coverage, as well as fraud resolution and credit and identity restoration services at no cost to the members."
Health Net not only settled with the Connecticut state attorney general's office (for $250,000) but also with the Connecticut Insurance Commission, which reached a settlement with Health Net in which the insurer had to pay the state $375,000 in penalties for failing to safeguard the personal information of its members from misuse by third parties.
Dom Nicastro is a contributing writer. He edits the Medical Records Briefings newsletter and manages the HIPAA Update Blog.
- Two-Midnight Rule Must be Fixed or Replaced, Say Providers
- Don't Underestimate Emotional Intelligence
- The Secret to Physician Engagement? It's Not Better Pay
- Care Coordination Tough to Define, Measure
- Yale New Haven Health Partners with Tenet Healthcare in CT
- Physicians Take SGR Repeal Message to Washington
- Size Matters in Antibiotic Overuse
- CDC Warns of Antibiotic Overuse in Hospitals
- 4 Reasons PCMH Principles Aren't Going Away
- SCOTUS Review of NC Board Case 'A Very Big Deal' to Providers