Topics
More on Risk Management

Care New England Health system to pay $400,000 over HIPAA violation

In Nov. 2012, Women & Infants reported a data breach after discovering that two backup tapes went missing.

Rhode Island's Care New England Health system has been fined $400,000 by the Office for Civil Rights for alleged HIPAA violations. The federal agency said the hospital lacked updated business associate agreements with the Women & Infants Hospital of Rhode Island, which the system owns.

According to the settlement, in Nov. 2012, Women & Infants reported a data breach after discovering that two backup tapes including unencrypted personal health information on 14,000 people went missing.

[Also: 8.8 million patient health records breached in August, report says]

In responding to the claim, the OCR found that the business associate agreement between Women & Infants and Care New England Health, which was in charge of providing technical support to the hospital, had not been updated since 2005.

While the settlement does not mean Care New England admits guilt, the system did agree to follow a corrective action plan to come into compliance. That includes making sure it has updated business associate agreements with all facilities in the system.

Twitter: @HenryPowderly
Contact the author: henry.powderly@himssmedia.com