DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Women & Infants Hospital to Pay $150,000 to Settle Data Breach Allegations Involving Massachusetts Patients

Posted on July 23, 2014 by Dissent

There’s a follow-up to a breach disclosed in November 2012:

Women & Infants Hospital of Rhode Island (WIH) has agreed to pay $150,000 to resolve allegations that it failed to protect the personal information and protected health information of more than 12,000 patients in Massachusetts, Attorney General Martha Coakley announced today.

The consent judgment, approved yesterday by Suffolk Superior Court Judge Carol Ball, resulted from a data breach reported to the AG’s Office in November 2012 that included patients’ names, dates of birth, Social Security numbers, dates of exams, physicians’ names, and ultrasound images.

“Personal information and protected health information must be properly safeguarded by hospitals and other healthcare entities,” AG Coakley said. “This data breach put thousands of Massachusetts consumers at risk, and it is the hospital’s responsibility to ensure that this type of event does not happen again.”

In April 2012, WIH realized that it was missing 19 unencrypted back-up tapes from two of its Prenatal Diagnostic Centers, one located in Providence, Rhode Island and the other located in New Bedford, Massachusetts. The back-up tapes contained the personal information and protected health information of 12,127 Massachusetts residents.

In the summer of 2011, these back-up tapes were supposed to be sent to a central data center at WIH’s parent company, Care New England Health System and then shipped off-site in order to transfer legacy radiology information to a new picture archiving and communications system. However, due to an inadequate inventory and tracking system, WIH allegedly did not discover the tapes were missing until the spring of 2012. Due to deficient employee training and internal policies, the breach was not properly reported under the breach notification statute to the AG’s Office and to consumers until the fall of 2012.

Under the terms of the settlement, WIH has agreed to take steps to ensure future compliance with state and federal data security laws and regulations, including maintaining an up-to-date inventory of the locations, custodians, and descriptions of unencrypted electronic media and paper patient charts containing personal information and protected health information. The hospital also agreed to perform a review and audit of security measures and to take any corrective measures recommended in the review.

According to the settlement, WIH will pay a $110,000 civil penalty, $25,000 for attorney’s fees and costs, and a payment of $15,000 to a fund to be used by the Attorney General’s Office to promote education concerning the protection of personal information and protected health information and a fund for future data security litigation.

The AG’s Office is focused on ensuring that health care practices and their business associates abide by the state’s date security laws and federal data privacy requirements under HIPAA and the HITECH Act. Efforts include the $750,000 settlement with South Shore Hospital in May 2012, resolving allegations that it failed to protect the personal information and protected health information of more than 800,000 patients. In 2013, the AG’s Office reached a $140,000 settlement with medical billing company Goldthwait Associates and its client pathology groups over allegations that sensitive medical records and confidential billing information for tens of thousands of Massachusetts patients were improperly disposed of at a public dump in Georgetown.

This matter is being handled by Assistant Attorney General Shannon Choy-Seymour of the Health Care Division.

SOURCE: Massachusetts Attorney General Martha Coakley

No related posts.

Category: Uncategorized

Post navigation

← IRS employee charged with ID theft of co-workers
MobilexUSA Notifies Affected Patients of Possible Privacy Breach →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • National Health Care Fraud Takedown Results in 324 Defendants Charged in Connection with Over $14.6 Billion in Alleged Fraud
  • Swiss Health Foundation Radix Hit by Cyberattack Affecting Federal Data
  • Russian hackers get 7 and 5 years in prison for large-scale cyber attacks with ransomware, over 60 million euros in bitcoins seized
  • Bolton Walk-In Clinic patient data leak locked down (finally!)
  • 50 Customers of French Bank Hit by Insider SIM Swap Scam
  • Ontario health agency atHome ordered to inform 200,000 patients of March data breach
  • Fact-Checking Claims By Cybernews: The 16 Billion Record Data Breach That Wasn’t
  • Horizon Healthcare RCM discloses ransomware attack in December
  • Disgruntled IT Worker Jailed for Cyber Attack, Huddersfield
  • Hacker helped kill FBI sources, witnesses in El Chapo case, according to watchdog report

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • The Trump administration is building a national citizenship data system
  • Supreme Court Decision on Age Verification Tramples Free Speech and Undermines Privacy
  • New Jersey Issues Draft Privacy Regulations: The New
  • Hacker helped kill FBI sources, witnesses in El Chapo case, according to watchdog report
  • Germany Wants Apple, Google to Remove DeepSeek From Their App Stores
  • Supreme Court upholds Texas law requiring age verification on porn sites
  • Justices nix Medicaid ‘right’ to choose doctor, defunding Planned Parenthood in South Carolina

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.