DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Former Owners of Goldthwait Associates, Pathology Groups Agree to Pay $140,000 to Settle Claims that Patients’ Health Information was Disposed of Improperly

Posted on January 7, 2013 by Dissent

Remember the  2010 case where four Massachusetts pathology groups’ records were found dumped improperly by their business associate, Goldthwait Associates?  There’s been a settlement in the case:

BOSTON – Former owners of a Marblehead-based medical billing practice and four pathology groups have agreed to collectively pay $140,000, settling allegations that sensitive medical records and confidential billing information for tens of thousands of Massachusetts patients were improperly disposed of at a public dump, Attorney General Martha Coakley announced today.

The complaint, filed in Suffolk Superior Court along with consent judgments that were approved today, alleges that Joseph and Louise Gagnon, d/b/a Goldthwait Associates, violated state data security laws when they mishandled and improperly disposed of medical records containing personal information and protected health information from four Massachusetts pathology groups at the Georgetown Transfer Station. The medical records contained information for more than 67,000 residents including names, Social Security numbers, and medical diagnoses that were not redacted or destroyed when they were dumped.

“Personal health information must be safeguarded as it passes from patients to doctors to medical billers and other third-party contractors,” AG Coakley said. “We believe this data breach put thousands of patients at risk, and it is the obligation of all parties involved to ensure that sensitive information is disposed of properly to prevent this from happening again.”

This matter came to the public’s attention in July 2010 when a Boston Globe photographer was disposing of his own trash at the Georgetown Transfer Station and observed a large mound of paper which, upon closer inspection, he determined were medical records. His discovery was first reported in the Globe shortly thereafter.

The other defendants involved in this settlement are Dr. Kevin Dole, former President of Chestnut Pathology Services, P.C.; Milford Pathology Associates, P.C.; Milton Pathology Associates, P.C.; and Pioneer Valley Pathology Associates, P.C.

The AG’s Office alleges that these pathology groups violated HIPAA regulations by failing to have appropriate safeguards in place to protect the personal information they provided to Goldthwait Associates, and violated state data security regulations by not taking reasonable steps to select and retain a service provider that would maintain appropriate security measures to protect such confidential information.

According to the complaint, the Gagnons ran Goldthwait Associates – which primarily provided medical billing services for pathology groups – and received sensitive medical records and billing information of clients in order to send medical bills on behalf of the groups. The Gagnons retired from Goldthwait Associates and the medical billing business in 2010.

Each of the four pathology groups and the Gagnons agreed to entry of consent judgments to resolve the AG’s allegations. Under the settlements, the defendants have agreed to pay a total of $140,000 for civil penalties, attorney fees, and a data protection fund to support efforts to improve the security and privacy of sensitive health and financial information in Massachusetts.

The AG’s Office is focused on ensuring that health care practices and their business associates abide by the state and federal data privacy requirements. Recent efforts include the $750,000 settlement with South Shore Hospital in May 2012, resolving allegations that it failed to protect the personal and confidential health information of more than 800,000 patients.

AG Coakley is also leading an educational effort in the area of data privacy. A first-of-its-kind data privacy training – sponsored jointly by the AG’s Office and the Massachusetts Medical Society – was held in October 2012 and focused on health care entities, including speakers from state and federal government and the private sector. A second training is being held this Thursday in cooperation with the Massachusetts Hospital Association.

This matter is being handled by Assistant Attorneys General Wendoly Ortiz Langlois of the Health Care Division and Shannon Choy-Seymour of the Consumer Protection Division.

Category: Health Data

Post navigation

← Panasonic Czech Republic and Slovakia Hacked, Defaced & Data Leaked
Former Texas HHS employee charged with identity theft; Hundreds may be impacted →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Texas Doctor Who Falsely Diagnosed Patients as Part of Insurance Fraud Scheme Sentenced to 10 Years’ Imprisonment
  • VanHelsing ransomware builder leaked on hacking forum
  • Hack of Opexus Was at Root of Massive Federal Data Breach
  • ‘Deep concern’ for domestic abuse survivors as cybercriminals expected to publish confidential abuse survivors’ addresses
  • Western intelligence agencies unite to expose Russian hacking campaign against logistics and tech firms
  • Disrupting Lumma Stealer: Microsoft leads global action against favored cybercrime tool
  • Researchers Scrape 2 Billion Discord Messages and Publish Them Online
  • Privilege Under Fire: Protecting Forensic Reports in the Wake of a Data Breach
  • Hacker who breached communications app used by Trump aide stole data from across US government
  • Massachusetts hacker to plead guilty to PowerSchool data breach (1)

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Widow of slain Saudi journalist can’t pursue surveillance claims against Israeli spyware firm
  • Researchers Scrape 2 Billion Discord Messages and Publish Them Online
  • GDPR is cracking: Brussels rewrites its prized privacy law
  • Telegram Gave Authorities Data on More than 20,000 Users
  • Police secretly monitored New Orleans with facial recognition cameras
  • Cocospy stalkerware apps go offline after data breach
  • Drugmaker Regeneron to acquire 23andMe out of bankruptcy

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.