DataBreaches.net

DataBreaches.net

The Office of Inadequate Security

Menu
  • Breach Laws
  • About
  • Donate
  • Contact
  • Privacy
  • Transparency Reports
Menu

Lahey Clinic Hospital settles OCR charges stemming from theft of laptop used with CT scanner

Posted on November 24, 2015 by Dissent

Hot off the presses: there’s been another settlement announced by OCR. This one involves Lahey Hospital and Medical Center (Lahey Clinic Hospital), who have agreed to pay $850,000 and to adopt a robust corrective action plan to correct deficiencies in its HIPAA compliance program.

Lahey is a nonprofit teaching hospital affiliated with Tufts Medical School, providing primary and specialty care in Burlington, Massachusetts. The incident involved the theft of a laptop with 599 patients’ protected health information.  Although there is no press release issued yet, according to the Resolution Agreement, Lahey notified HHS in October, 2011 that the unencrypted laptop was used in connection with a computerized tomography (“CT”) scanner. The laptop was reportedly stolen from an unlocked treatment room off of the inner corridor of Lahey’s Radiology Department.

In investigating the incident, OCR found that

  • Lahey failed to conduct an accurate and thorough analysis of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of its ePHI as part of its security management process. See 45 C.F.R. §164.308(a)(1)(ii)(A).
  • Lahey failed to implement reasonable and appropriate physical safeguards for a workstation that accesses ePHI to restrict access to authorized users. See 45 C.F.R. § 164.310(c).
  • With respect to the workstation, Lahey failed to implement policies and procedures that govern the receipt and removal of hardware and electronic media that contain ePHI into and out of its facility, and the movement of these items within its facility. See 45 C.F.R. § 164.310(d)(1).
  • Lahey failed to assign a unique user name for identifying and tracking user identity with respect to the aforementioned workstation. See 45 C.F.R. § 164.312(a)(2)(i).
  • Lahey did not implement a mechanism to record and examine activity on the workstation at issue in this breach. See 45 C.F.R. § 164.312(b).
  • Lahey impermissibly disclosed the ePHI of 599 individuals for a purpose not permitted by the Privacy Rule. See 45 C.F.R. § 164.502(a).

In addition to the $850,000 fee, Lahey has agreed, without any admissions or concessions, to a multi-element corrective action program, detailed in the Resolution Agreement.

Related Posts:

  • Lahey Clinic breach: how seriously are some entities…
  • Lifespan Pays $1,040,000 to OCR to Settle…
  • QCA Health Plan settles HHS charges stemming from…
  • Beverly Hospital courier loses patients’ lab forms
  • St. Elizabeth’s Medical Center agrees to settle…

Post navigation

← Fifth arrest in TalkTalk breach as 18-year-old from Wales held on suspicion of blackmail
Anthem Fires Back at Data Breach Suit →

Sponsored or Paid Posts

This site doesn’t accept sponsored posts and doesn’t respond to requests about them.

Have a News Tip?

Email:

Breaches[at]Protonmail.ch
Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Telegram: @DissentDoe

Browse by News Section

Latest Posts

  • Proliance Surgeons notifying 437,392 patients after ransomware attack earlier this year
  • After $50 Million Breach, KyberSwap Faces Hacker’s Shocking Demands
  • Hendersonville city employees target of cybersecurity breach
  • Ukrainian gets 8-year sentence for running marketplace for Americans’ data
  • Some city data was stolen during cyber breach; full scope remains unknown, Long Beach says
  • More than 1 million Michiganders affected by Welltok cyberattack
  • Line operator says 440,000 personal records leaked in data breach
  • Ransomware group ‘Black Basta’ has raked in more than $100 million -researchers

Please Donate

If you can, please donate XMR to our Monero wallet because the entities whose breaches we expose are definitely not supporting our work and are generally trying to chill our speech!

Donate- Scan QR Code   Donate!

Social Media

Find me on Infosec.Exchange.

I am also on Telegram @DissentDoe.

RSS

Grab the RSS Feed

Copyright

© 2009 – 2023, DataBreaches.net and DataBreaches LLC. All rights reserved.

HIGH PRAISE, INDEED!

“You translate “Nerd” into understandable “English” — Victor Gevers of GDI Foundation, talking about DataBreaches.net

©2023 DataBreaches.net