Two US health care outlets - Columbia University and the New York and Presbyterian Hospital (NYP) - have paid a whopping $4.8m to settle charges after they inadvertently leaked the records of 6,800 patients on the web. This week the judgment was passed – four years after the incident - that they violated the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy and Security Rules by failing to secure thousands of patients' electronic protected health information held on their network. On the US department of Health and Human Services website it stated that the investigation revealed the data breach happened when a physician employed by Columbia University tried to deactivate a personally-owned computer server on the network which contained NYP and the network of patient data.