DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

CT AG Jepsen, Hartford Hospital, Contractor Reach Agreement Resolving Investigation into Breach of Unencrypted Patient Information

Posted on November 6, 2015 by Dissent

There’s an update to a breach that I previously noted in 2012, and it reinforces the importance of your business associate contracts and the importance of monitoring them if you’re a HIPAA-covered entity:

Hartford Hospital and the EMC Corporation will pay $90,000 and have agreed to institute additional training and control measures to resolve an investigation into the 2012 theft of a laptop containing unencrypted patient information, Attorney General George Jepsen said today.

The unencrypted protected health information (PHI) of approximately 8,883 Connecticut residents was on a laptop that was stolen from an EMC employee’s home in June 2012. EMC had been retained by Hartford Hospital to assist on a quality improvement project on hospital readmissions. The employee had been employed by and received the laptop that was stolen from a company that EMC had previously acquired. While the laptop has not been recovered, the hospital maintains that there is no evidence that the information has been misused.

In an assurance of voluntary compliance signed this week, the hospital and the company have agreed to implement or continue new training requirements and other policies in response to the breach.

“The responsibilities of those who maintain and use personal information under HIPAA and Connecticut’s privacy laws are clear and are appropriately intended to protect the privacy of the patients,” Attorney General Jepsen said. “All healthcare providers and any contractors who work with healthcare providers should pay close attention to these responsibilities and review their internal controls and policies to ensure that they’re doing all they possibly can to comply with the law and to keep this information safe.”

As a result of the data breach, Hartford Hospital instituted a number of corrective measures to ensure that contractual agreements are properly executed with vendors, that minimum privacy and security controls are instituted when PHI will be shared with a vendor and created new contract templates that incorporate applicable provisions of the Health Insurance Portability and Accountability Act (HIPAA). The hospital also enhanced its annual mandatory compliance training and developed new training for business managers about their HIPAA obligations.

In addition, the agreement with the attorney general requires the hospital to comply with privacy standards and provisions under HIPAA and to utilize a combination of hardware and software to encrypt files or data containing PHI prior to its transmission or transfer, when applicable. The hospital must submit a report in one year to demonstrate its implementation of the corrective measures.

Further, the agreement requires EMC to maintain reasonable policies requiring the encryption of all PHI stored on laptops or other portable devices and transmitted across wireless or public networks and to maintain reasonable polices for employees relating to the storage, access and transfer of PHI outside of EMC premises. The company must provide training to those employees responsible for handling or using PHI and maintain policies for responding to events involving unauthorized acquisition, access, use or disclosure of PHI.

The $90,000 payment pursuant to the agreement will be deposited in the state’s General Fund.

Assistant Attorneys General Thomas Ryan and Matthew Fitzsimmons, head of the Privacy and Data Security Department, assisted the Attorney General with this matter.

Please click here to view the assurance of voluntary compliance.

SOURCE: Attorney General George Jepsen


Related:

  • HIPAA Compliance and Breach Communications: Helpful Tips for SMBs
  • IRS’s Top 10 Identity Theft Prosecutions
  • The Secret IRS Files: Trove of Never-Before-Seen Records Reveal How the Wealthiest Avoid Income Tax
  • McAlisters Deli, Moe’s Southwest Grill, Schlotzsky’s Notice of Data Breach to Consumers
  • Small-Scale Violations of Medical Privacy Often Cause the Most Harm
Category: Health DataSubcontractorTheftU.S.

Post navigation

← Investigation continues into Cardinals’ hacking of Astros system
Hackers who hacked CIA Director’s personal e-mail claim hack of FBI database →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Ransomware incident responder gave info to BlackCat cybercriminals during negotiations, DOJ alleges
  • 45,000 malicious IP addresses taken down in international cyber operation
  • The Broken Records: tracing the human cost of the 2022 British MoD leak
  • Telus Digital confirms breach after ShinyHunters claims 1 petabyte data theft
  • China’s CERT warns OpenClaw can inflict nasty wounds
  • Bell Ambulance data breach impacted over 238,000 people
  • Lotte Card fined 9.6 billion won for leaking users’ social registration numbers
  • Handala claims responsibility for attack on medical device maker Stryker
  • Police Scotland fined £66k for extracting and sharing mobile phone data
  • The rise of teen hackers ‘makes for a good headline’, but cyber crime activities peak later in life

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • New data shows increase in FBI searches of Americans’ data last year
  • CalPrivacy Fines PlayOn Sports $1.1 Million for CCPA Violations Involving Student Privacy
  • 17 States Sues Trump Administration Over Unlawful Data Demands Targeting Colleges
  • Privacy watchdogs sound alarm over US bid to get travellers’ social media
  • Petition filed over misuse of protesters’ data by Kenyan government and telcos

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: Dissent.73

Contact Me

Email: info[at]databreaches.net
Security Issue: security[at]databreaches.net
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: Dissent.73
DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.