Skip to Main Content

HIPAA Enforcement Action

Federal regulators recently penalized a self-funded employer health plan following a ransomware attack that exposed sensitive personal and health-related information. The enforcement action resulted in a $245,000 payment to the government along with a two-year corrective action plan requiring ongoing oversight and remediation efforts.

The central issue was the plan’s failure to conduct a thorough and documented risk analysis, which is a foundational requirement under HIPAA’s Security Rule.

Regulators emphasized that organizations must identify where protected health information (PHI) is stored, assess vulnerabilities, and maintain clear documentation of their security evaluations. Lapses in these areas, particularly failing to analyze risks to electronic PHI, continue to be a common basis for enforcement actions, reinforcing the need for strong cybersecurity, formal risk analysis processes, and ongoing data governance practices.

Note: The HIPAA Privacy and Security requirements also applies to level funded employer group health plans and fully insured plans that receive, store or work with PHI.

Resources

 

While every effort has been taken in compiling this information to ensure that its contents are totally accurate, neither the publisher nor the author can accept liability for any inaccuracies or changed circumstances of any information herein or for the consequences of any reliance placed upon it. This publication is distributed on the understanding that the publisher is not engaged in rendering legal, accounting, or other professional advice or services. Readers should always seek professional advice before entering into any commitments.