Athens Orthopedic Settles with OCR for $1.5M for Data Breach
Friday, October 2, 2020

The U.S. Department of Health and Human Services’ Office for Civil Rights (OCR) has announced that it has settled potential violations of HIPAA with Athens Orthopedic Clinic PA (Athens) for $1.5 million, following an investigation of a data breach that occurred in 2016.

The data breach compromised the protected health information of 208,557 individuals when the information may have been stolen and posted online for sale. Two days later, the hacker requested payment of money in exchange for return of the stolen database. It is reported that the hacker was able to access the database through the use of a vendor’s credentials.

The OCR’s investigation found that Athens had systemic noncompliance with both the HIPAA Privacy and Security Rules. In addition to the monetary settlement, Athens will also implement a corrective action plan and be monitored for two years.

 

NLR Logo

We collaborate with the world's leading lawyers to deliver news tailored for you. Sign Up to receive our free e-Newsbulletins

 

Sign Up for e-NewsBulletins