DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Topeka healthcare company fined for failing to protect personal information

Posted on January 24, 2018 by Dissent

I like seeing state attorneys general take enforcement action over breaches, even if the amount of the monetary penalties is quite small, as in this case. This case may remind people who have offices or satellite offices in their homes that they can’t just leave employee or patient data lying around where anyone can see it or easily access it.

TOPEKA – (January 18, 2018) – A Topeka healthcare company and its owners have been fined for failing to protect patient and employee records, Attorney General Derek Schmidt said.

Pearlie Mae’s Compassion and Care LLC, and Ann Marie Kaiser and Jenell Jones, the owners of the company that provides care for disabled consumers, agreed to pay an $8,750 civil penalty for violations of the Wayne Owen Act, which is part of the Kansas Consumer Protection Act. The consent judgment, which was approved last week by District Judge Franklin R. Theis in Shawnee County District Court, also requires the defendants to make changes to their business practices in accordance with state laws and to pay the attorney general’s investigation costs.

In June 2017, during the course of assisting the Topeka Police Department in executing a search warrant, special agents of the Kansas Attorney General’s office observed patient and employee records containing personal information in Kaiser’s home, which also served as one office location for the company. The records were found in open view, unsecured and accessible to anyone in the residence, including persons who had no legitimate business reason to access the personal information in the records. A lawsuit filed by Schmidt in June alleged the defendants failed to implement and maintain reasonable procedures and practices to protect personal information and by failing to take reasonable steps to destroy or arrange for the secure destruction of records containing personal information when the records no longer are to be used.

“Personal information” includes information such as a social security number, driver’s license number, financial account number or credit or debit card number that can be misused to commit identity theft or otherwise harm the person whose information is compromised. It also includes any information, such as medical records, for which a security obligation is imposed by federal or state statute. Under Kansas law, businesses that collect the personal information of others have a duty to safeguard it.

A copy of the consent judgment is available here .

Source: Kansas Attorney General Derek Schmidt

h/t, WIBW

Related posts:

  • Topeka business fined $70,000 for dumping personal information in trash
Category: Health DataOf Note

Post navigation

← ICE Releases Personal Information Of Immigrant-Crime Hotline Users
MY: Personal Data Protection Commission to probe data leak →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Terrible tales of opsec oversights: How cybercrooks get themselves caught
  • International Criminal Court hit with cyber attack during NATO summit
  • Pembroke Regional Hospital reported canceling appointments due to service delays from “an incident”
  • Iran-linked hackers threaten to release emails allegedly stolen from Trump associates
  • National Health Care Fraud Takedown Results in 324 Defendants Charged in Connection with Over $14.6 Billion in Alleged Fraud
  • Swiss Health Foundation Radix Hit by Cyberattack Affecting Federal Data
  • Russian hackers get 7 and 5 years in prison for large-scale cyber attacks with ransomware, over 60 million euros in bitcoins seized
  • Bolton Walk-In Clinic patient data leak locked down (finally!)
  • 50 Customers of French Bank Hit by Insider SIM Swap Scam
  • Ontario health agency atHome ordered to inform 200,000 patients of March data breach

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • The Trump administration is building a national citizenship data system
  • Supreme Court Decision on Age Verification Tramples Free Speech and Undermines Privacy
  • New Jersey Issues Draft Privacy Regulations: The New
  • Hacker helped kill FBI sources, witnesses in El Chapo case, according to watchdog report
  • Germany Wants Apple, Google to Remove DeepSeek From Their App Stores
  • Supreme Court upholds Texas law requiring age verification on porn sites
  • Justices nix Medicaid ‘right’ to choose doctor, defunding Planned Parenthood in South Carolina

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.