On the Insider Threat, PCI and Risk Management
Let me share with you some highlights of recent podcast inte…
Eligible |
![]() |
Pharmacy chain Rite Aid Corp. has agreed to pay a $1 million fine and take corrective action to settle federal charges that it violated the HIPAA privacy rule and the FTC Act when some of its stores improperly disposed of prescription information in dumpsters.
The Department of Health and Human Services levied the fine and required corrective action to settle the HIPAA-related charges. In addition, the Federal Trade Commission required another set of corrective actions, including frequent security audits.
The settlement comes after a four-year investigation that originated when media reports revealed that stores in various cities disposed of prescriptions and labeled pill bottles in open dumpsters that were accessible to the public.
"Disposing of individuals' health information in an industrial trash container accessible to unauthorized persons is not compliant with several requirements of the HIPAA privacy rule and exposes the individual's information to the risk of identity theft and other crimes," HHS said in a release.
Rite Aid has about 4,900 retail pharmacies.
The Rite Aid case is the second settlement as a result of a joint HHS and FTC investigation. The agencies settled a similar case against CVS Caremark in February 2009. That settlement resulted a $2.25 million fine.
The FTC settlement requires the company to:
National Strategy for Trusted Identities in Cyberspace (Draft)..Next Topic
National Strategy for Trusted Identities in Cyberspace (Draft)..Next Topic
National Strategy for Trusted Identities in Cyberspace (Draft)..Next Topic
National Strategy for Trusted Identities in Cyberspace (Draft)..Next Topic
GAO: VA Needs to Resolve Long-Standing Infosec Weaknesses..Next Topic
GAO: VA Needs to Resolve Long-Standing Infosec Weaknesses..Next Topic
GAO: VA Needs to Resolve Long-Standing Infosec Weaknesses..Next Topic
GAO: VA Needs to Resolve Long-Standing Infosec Weaknesses..Next Topic
GAO: VA Needs to Resolve Long-Standing Infosec Weaknesses..Next Topic
NIST SP 800-122: Guide to Protecting the Confidentiality of Personally Identifiable..Next Topic