DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

CT AG Jepsen, Hartford Hospital, Contractor Reach Agreement Resolving Investigation into Breach of Unencrypted Patient Information

Posted on November 6, 2015 by Dissent

There’s an update to a breach that I previously noted in 2012, and it reinforces the importance of your business associate contracts and the importance of monitoring them if you’re a HIPAA-covered entity:

Hartford Hospital and the EMC Corporation will pay $90,000 and have agreed to institute additional training and control measures to resolve an investigation into the 2012 theft of a laptop containing unencrypted patient information, Attorney General George Jepsen said today.

The unencrypted protected health information (PHI) of approximately 8,883 Connecticut residents was on a laptop that was stolen from an EMC employee’s home in June 2012. EMC had been retained by Hartford Hospital to assist on a quality improvement project on hospital readmissions. The employee had been employed by and received the laptop that was stolen from a company that EMC had previously acquired. While the laptop has not been recovered, the hospital maintains that there is no evidence that the information has been misused.

In an assurance of voluntary compliance signed this week, the hospital and the company have agreed to implement or continue new training requirements and other policies in response to the breach.

“The responsibilities of those who maintain and use personal information under HIPAA and Connecticut’s privacy laws are clear and are appropriately intended to protect the privacy of the patients,” Attorney General Jepsen said. “All healthcare providers and any contractors who work with healthcare providers should pay close attention to these responsibilities and review their internal controls and policies to ensure that they’re doing all they possibly can to comply with the law and to keep this information safe.”

As a result of the data breach, Hartford Hospital instituted a number of corrective measures to ensure that contractual agreements are properly executed with vendors, that minimum privacy and security controls are instituted when PHI will be shared with a vendor and created new contract templates that incorporate applicable provisions of the Health Insurance Portability and Accountability Act (HIPAA). The hospital also enhanced its annual mandatory compliance training and developed new training for business managers about their HIPAA obligations.

In addition, the agreement with the attorney general requires the hospital to comply with privacy standards and provisions under HIPAA and to utilize a combination of hardware and software to encrypt files or data containing PHI prior to its transmission or transfer, when applicable. The hospital must submit a report in one year to demonstrate its implementation of the corrective measures.

Further, the agreement requires EMC to maintain reasonable policies requiring the encryption of all PHI stored on laptops or other portable devices and transmitted across wireless or public networks and to maintain reasonable polices for employees relating to the storage, access and transfer of PHI outside of EMC premises. The company must provide training to those employees responsible for handling or using PHI and maintain policies for responding to events involving unauthorized acquisition, access, use or disclosure of PHI.

The $90,000 payment pursuant to the agreement will be deposited in the state’s General Fund.

Assistant Attorneys General Thomas Ryan and Matthew Fitzsimmons, head of the Privacy and Data Security Department, assisted the Attorney General with this matter.

Please click here to view the assurance of voluntary compliance.

SOURCE: Attorney General George Jepsen

Category: Health DataSubcontractorTheftU.S.

Post navigation

← Investigation continues into Cardinals’ hacking of Astros system
Hackers who hacked CIA Director’s personal e-mail claim hack of FBI database →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Fresno County fell victim to $1.6M phishing scam in 2020. One suspected has been arrested, another has been indicted.
  • Ransomware Attack on ADP Partner Exposes Broadcom Employee Data
  • Anne Arundel ransomware attack compromised confidential health data, county says
  • Australian national known as “DR32” sentenced in U.S. federal court
  • Alabama Man Sentenced to 14 Months in Connection with Securities and Exchange Commission X Hack that Spiked Bitcoin Prices
  • Japan enacts new Active Cyberdefense Law allowing for offensive cyber operations
  • Breachforums Boss “Pompompurin” to Pay $700k in Healthcare Breach
  • HHS Office for Civil Rights Settles HIPAA Cybersecurity Investigation with Vision Upright MRI
  • Additional 12 Defendants Charged in RICO Conspiracy for over $263 Million Cryptocurrency Thefts, Money Laundering, Home Break-Ins
  • RIBridges firewall worked. But forensic report says hundreds of alarms went unnoticed by Deloitte.

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Massachusetts Senate Committee Approves Robust Comprehensive Privacy Law
  • Montana Becomes First State to Close the Law Enforcement Data Broker Loophole
  • Privacy enforcement under Andrew Ferguson’s FTC
  • “We would be less confidential than Google” – Proton threatens to quit Switzerland over new surveillance law
  • CFPB Quietly Kills Rule to Shield Americans From Data Brokers
  • South Korea fines Temu for data protection violations
  • The BR Privacy & Security Download: May 2025

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.