Alaska HIPAA Penalty: $1.7 MillionMedicaid Program Cited for Breach, Security Shortcomings
The Alaska Department of Health and Social Services has agreed to pay $1.7 million to settle a HIPAA case involving a stolen USB drive potentially containing Medicaid beneficiaries' health information.
The Department of Health and Human Service's Office for Civil Rights' list of major breaches says only 501 people were affected by the October 2009 incident. But the settlement agreement cites a long list of security shortcomings at the state agency.
As part of the settlement, Alaska DHSS also agreed to a corrective action plan in which the agency is required to "review, revise, and maintain policies and procedures to ensure compliance with the HIPAA Security Rule." An external monitor will report back to OCR regularly on the state's ongoing compliance efforts, according to the settlement agreement.
The settlement is OCR's first HIPAA enforcement action against a state agency.
The breach incident involved a portable USB storage device containing protected health information that was stolen from the vehicle of a DHSS computer technician in October 2009.
An OCR investigation determined that DHSS had not completed a risk assessment; had not implemented sufficient risk management measures; had not completed security training for DHSS workforce members; and had not implemented device and media controls.
"Covered entities must perform a full and comprehensive risk assessment and have in place meaningful access controls to safeguard hardware and portable devices," OCR director Leon Rodriguez said in a statement.