The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has levied a $240,000 fine against Providence Medical Institute in Southern California due to violations of the Health Insurance Portability and Accountability Act Security Rule. This enforcement action comes in response to a series of ransomware attacks that exposed the electronic protected health information of 85,000 individuals.
The details: The provider was hit by three consecutive ransomware attacks between February and March 2018, which encrypted sensitive patient data, rendering it inaccessible. OCR’s investigation found that the facility failed to have a business associate agreement with its IT vendor, Creative Solutions in Computers (CSnC), and did not implement adequate security controls to protect the electronic protected health information.
Key findings:
- The ransomware attacks affected patient names, addresses, Social Security numbers, and financial details.
- OCR discovered that Providence Medical Institute did not secure its systems with encryption, leaving patient data vulnerable to attackers.
- The healthcare provider was using outdated IT infrastructure, including unsupported operating systems and poorly configured firewalls.
The big picture: The 264% increase in ransomware attacks on healthcare organizations since 2018 has heightened the scrutiny around HIPAA compliance. Compliance with HIPAA rules is not optional—failures in cybersecurity can lead to hefty fines and damage to a company’s reputation.
What they’re saying: “Failures to fully implement all of the HIPAA Security Rule requirements leave HIPAA covered entities and business associates vulnerable to cyberattacks at the expense of the privacy and security of patients’ health information,” said OCR Director Melanie Fontes Rainer. “The healthcare sector needs to get serious about cybersecurity and complying with HIPAA.”
.




