
One great way to ensure your practice avoids HIPAA breaches is to learn from the mistakes other practices have made. It’s a good idea to keep track of organizations that recently made news for HIPAA issues and dig into what happened to cause their leaks.
Check out three recent HIPAA breaches and discover which issues caused these problems so you can secure patient privacy at your practice.
-
Kaiser Permanente Pays $47.5 Million
Earlier this month, healthcare behemoth Kaiser Permanente settled a class action lawsuit that centered around the fact that the protected health information (PHI) and personal data of more than 13 million patients was exposed to tech organizations through the use of tracking cookies on the firm’s website.
Under the terms of the agreement, Kaiser Permanente will pay $47.5 million to affected patients. Organizations that may have had access to the patients’ data due to the tracking cookie included Microsoft, Meta, Google, Twitter and others.
Essential: If your practice has a website, make sure your tracking cookies have consent notices that ensure that patients are aware of any risks on your site, and work with a qualified technological security consultant so you don’t inadvertently leak any PHI through your website’s tracking cookies.
-
Rehab Centers Reach $182,000 Settlement
In October, a rehabilitation and skilled nursing provider in Delaware was alleged to have posted patients’ PHI to social media without having signed HIPAA authorizations on file. The organization also allegedly failed to notify patients about the fact that their information was on social media. The posts consisted of success stories of patients who had been treated by the organization.
Important: Only certain PHI disclosures are permissible under the HIPAA rules, and if you share PHI outside of those options, you could be subject to breach accusations. Even if patients gladly agreed to let their information appear on social media, you still need a signed authorization on file under the law.
-
Data Breach Leads to $1.3 Million Settlement
A pharmacy service reached a $1.3 million settlement after accusations that patients’ PHI was accessed after unauthorized individuals were able to get into the organization’s website. Among the details that were leaked included patient names, dates of birth, contact information, treatment details and diagnoses.
Don’t forget: You should have appropriate cybersecurity practices in place to ensure that no one can access the data on your site. If you have a data or security lapse, investigate immediately to stop any issues from occurring.
| Don’t let your practice be a HIPAA breaches statistic! Expert Tracy Bird, FACMPE, CPC, can help you prevent patient privacy leaks during her 60-minute online training, Head Off Front Desk HIPAA Nightmares. Sign up today! |

