Lack of business associate agreement leads to $750,000 HIPAA fine
HCPRO Website, April 22, 2016
The Office for Civil Rights (OCR) made an example of its increased focus on business associate agreements (BAA) with its latest HIPAA settlement. Raleigh Orthopaedic Clinic, P.A. of North Carolina (ROC) agreed to pay $750,000 to settle charges that it violated HIPAA when it turned over X-ray films of approximately 17,300 patients to a third-party vendor without obtaining a BAA, HHS said.
OCR’s investigation began in April 2013 when ROC notified the agency about a possible breach. ROC contracted with a third party vendor to transfer old X-ray films into electronic files. The clinic sent the X-rays to the vendor without first obtaining a BAA. The vendor never provided the electronic files and an investigation by ROC revealed it was the victim of a scam. The vendor failed to create the electronic files and instead sold the X-rays to a recycling company in Ohio that harvested the silver from the films. ROC was not able to determine the location of any X-rays it entrusted to the vendor. The missing X-rays were taken prior to 2008 and contained patients’ full names and dates of birth.
Along with the fine, ROC agreed to a corrective action plan that states ROC will provide OCR with a list of its business associates (BA) and BAAs as well as a revised BAA policy that identifies the individuals responsible for evaluating BAs and obtaining and maintaining BAAs.
OCR used the announcement to remind covered entities (CE) that they are responsible for scrutinizing all potential BAs and must obtain a BAA before granting any BA access to PHI.
OCR has made a point of emphasizing key aspects of HIPAA compliance like risk analysis and BAAs in a string of high-profile HIPAA settlements. CEs and BAs should be aware that this may indicate that the agency will focus on these areas during Phase 2 audits. Phase 2 of the HIPAA Audit Program began in March and, unlike Phase 1, will include BAs. The agency recently released updated Phase 2 audit protocols, the pre-audit screening questionnaire, and a sample BA listing template.
Most Popular
- Articles
-
- Don't forget the three checks in medication administration
- Note similarities and differences between HCPCS, CPT® codes
- Practice the six rights of medication administration
- Nursing responsibilities for managing pain
- Skills of effective case managers
- The consequences of an incomplete medical record
- Steps for maintaining patient privacy
- Prevent dehydration with nursing interventions
- Q&A: Primary, principal, and secondary diagnoses
- Neurological checks for head injuries
- E-mailed
-
- Peer review using a retired physicain without liability insurance
- The history and importance of the pinning ceremony
- The consequences of an incomplete medical record
- Q: Do patients need to renew HIPAA acknowledgements every year?
- Q&A: Atelectasis query for secondary diagnosis
- Know the medical gas cylinder storage requirements
- Identify all injuries and conditions to correctly code for multiple significant trauma
- Fetal non-stress tests represent important part of maternal and fetal health
- Clinically Speaking: Accidental puncture laceration
- Clarifying status indicator ’S’ and ’T’ procedures
- Searched