{"id":410,"date":"2019-01-28T10:23:00","date_gmt":"2019-01-28T15:23:00","guid":{"rendered":"http:\/\/www.kraftgrp.com\/uncategorized\/2018-was-a-record-year-for-hipaa-penalties\/"},"modified":"2019-09-28T17:05:29","modified_gmt":"2019-09-28T22:05:29","slug":"2018-was-a-record-year-for-hipaa-penalties","status":"publish","type":"post","link":"https:\/\/www.kraftgrp.com\/2018-was-a-record-year-for-hipaa-penalties\/","title":{"rendered":"2018 Was a Record Year for HIPAA Penalties"},"content":{"rendered":"
<\/p>\n
2018 turned out to be a year of record fines for HIPAA violations. Over $25 million in fines, with the mean fine being just over $2.5 million. Could your medical entity bear that financial burden? Would it suffer irreparable harm from the adverse publicity? And just what violations did these healthcare entities do to get scrutinized, investigated and penalized?<\/p>\n
Since 2016, settlements and fines from the Department of Health and Human Services\u2019 Office for Civil Rights (OCR)\u00a0have risen substantially<\/a>. Healthcare entities should expect that this trend may continue and remain committed to avoiding HIPAA security breaches, negligence and failure to follow long-standing policies.<\/p>\n 2018 Review of OCR Settlements<\/strong><\/p>\n Whether your business is a smaller, private entity or a large, public entity, OCR investigations are expensive and potentially damaging to your business\u2019s reputation. Prevention is our best defense \u2013 don\u2019t let these errors happen.<\/p>\n Don\u2019t forget about your State\u2019s Attorney General\u2019s Office<\/strong><\/p>\n Medical entities also saw a rise in fines\/monetary penalties from state attorney generals. While the penalties are not always for HIPAA violations, they are still a distraction from your healthcare entity\u2019s mission statement, requiring employees\u2019 time and financial resources devoted to defending you against violation of state laws and HIPAA violations. Some states have become more aggressive in enforcement of HIPAA violations. The Northeastern states \u2013 New Jersey, New York, Massachusetts, Connecticut and the District of Columbia \u2013 have stepped up their enforcement efforts along with Washington State (who has yet to announce a settlement amount with Aetna). Defendants in these actions include insurance companies, hospitals, medical groups and even a transcription company.<\/p>\n State settlement amounts have ranged from a low of $75,000 to a high of over $1,000,000.<\/p>\n Common sense and training along with competent managed IT services will help ensure that your business is at decreased risk of HIPAA fines and penalties.<\/strong><\/p>\n\n