Home -> Law Blog Directory -> Health Law Blogs -> HealthBlawg
(866) 635-2689 for Personal Injury or (866) 635-9402 for Criminal Defense
Find a Local Lawyer
Divorce (866) 635-6190
Personal Injury (866) 635-2689
Criminal Defense (866) 635-9402
Health Law
: HealthBlawgMass General and HIPAA, or The medical records that never returned
By David Harlow
OCR announced today that Massachusetts General Hospital settled a HIPAA violation claim, without admitting liability, for $1 million and an agreement to revamp procedures for taking patient records off premises. The case involved a stack of paper records left on the T (Boston's subway) consisting of protected health information for a couple hundred patients, including patients on the HIV service. (As an aside, HIV records are subject to super-deluxe Rube Goldberg-esque privacy protections in Massachusetts -- they need to be flagged so that patients can sign an additional release before they are shared, since even the fact of testing is private, though in my humble opinion the flagging vitiates some of the privacy we want to afford these records). For those of you keeping score at home, $1 million seems serious, but not Very Serious, like yesterday's news of the $4.3 million civil monetary penalty assessed by OCR against Cignet Health in Maryland. As I wrote yesterday, the Cignet CMP is more important as a warning to the community of covered entities that they had better take obligations under HIPAA seriously than as an action against Cignet, which appears to be spectacularly unresponsive to this and other government actions; it seems unlikely that the federales will ever collect the full $4.3 million. The world is now on notice that OCR is not afraid to pull the trigger on $1.5 million CMP per willful violation. The MGH settlement, however, seems to me to be more important than the Cignet case. MGH, home of the Ether Dome and all that, has agreed, in a Resolution Agreement and Corrective Action Plan that it will develop, and submit to OCR for review and approval, policies and procedures governing physical removal and transport of PHI, and laptop and USB drive encryption, that would have addressed the incident on the T. Policies and procedures must be distributed to the MGH workforce, training conducted for current and new employees, and any violation and remediation must be reported. In the time-honored tradition of fighting the last war, special attention is paid to the removal of PHI from the premises. No member of the workforce may remove PHI from the MGH premises other than for MGH work purposes, and not unless MGH certifies that he or she has received the requisite training on these policies and procedures, and reasonable and appropriate measures are taken to maintain the privacy of PHI taken off site. MGH's internal audit department will function as the monitor for this plan, subject to OCR review and approval of a monitoring plan (which is to provide for interviews of workforce members and surprise inspections) and regular reports. It is fascinating to me -- and possibly a wake-up call to folks concerned about loss of privacy due to digitization of health records -- that in this digital age, an age of lost laptops and stolen hard drives, an institution at the heart of Boston's identity as a medical Mecca is tripped up by carelessness with paper records. Mass General paid $1 million to settle accounts with OCR -- a far cry from the nickel Charlie needed to get off the MTA. It seems to me that both MGH and the rest of us ought to have learned to take better care of PHI by now. Perhaps this case will move folks a little further in the right direction. David Harlow
The Harlow Group LLC
Health Care Law and Consulting
Full post as published by HealthBlawg on February 24, 2011 (boomark / email).
Tenet Florida employee medical record theft
Tenet Employee Caught Stealing Medical Records: Your basic identity theft/credit card fraud case. But since it involves medical records, HIPAA is implicated, and the story indicates that the duo will be charged with criminal HIPAA violations...
More medical records abuses
It seems that UCLA Medical Center had a serial HIPAA violator on its payroll (until he or she was fired last year for checking out Britney Spears' medical record). See: More UCLA records abuses - Los Angeles Times...
HIPAA video
This week's HIPAA video: More video; this week, it's on a recent study of the implications of HIPAA on medical research and electronic medical records. Ain't the internet cool? Thanks, Al Gore!
HOSPITAL PRIVACY BREACH -- DELIVERY OF MEDICAL RECORDS TO GRAND JURY.
In responding to government or grand jury subpoenas for medical records, analysis under the Health Insurance Portability and Accountability Act of 1996 (?HIPAA?), may not be the end of the road...
HIPAA Update Seminar
On April 3, 2008, I will be discussing some of the most common HIPAA misinterpretations and burning questions still out there at a Compliance Seminar organized and offered through the NJ Medical Society of New Jersey...
Doctors' Confusion over HIPAA
A Los Angeles Times article by Lisa Zamosky comments on the confusion in doctors' offices regarding Health Insurance Portability and Accountability Act (HIPAA). The article points out that obtaining medical records is often harder for patients than the law allows: Under HIPAA, consumers have the right to access records documenting their health conditions, diagnoses and treatments...
COBRA Continuation of Healthcare Coverage after Layoff
Pensions and Health Care Coverage for Dislocated Workers
National Practitioner Data Bank Fact
NPDB identifies unprofessional healthcare practitioners
Military Veterans Benefits
How to obtain full range of benefits for veterans and dependnets
Military Veterans Benefits, Part 2
Training, Healthcare, and Death Benefits
Medical Records
To Stay out of Pharma's Hands
Marshall Astor
Over $1.35 million in property, art and jewelry returned in elder care abuse lawsuit.
Whole Foods
And Other Firms Sued by California Attorney General,
State Farm
Settles with Mississippi Attorney General
Ticketmaster Entertainment
Settles with New Jersey Attorney General
Medical Technology
Ventana Medical Systems Inc. pays CytoLogix Corp. $49 million patent infringement settlement.










