DOTmed Home MRI Oncology Ultrasound Molecular Imaging X-Ray Cardiology Health IT Business Affairs
News Home Parts & Service Operating Room CT Women's Health Proton Therapy Endoscopy HTMs Mobile Imaging
SEARCH
Current Location:
>
> This Story

starstarstarstarstar (1)
Log in or Register to rate this News Story
Forward Printable StoryPrint Comment
advertisement

 

advertisement

 

U.S. Healthcare Homepage

Daniel Kelsey AHRA hires chief executive officer

Robert Sledd Owens & Minor names board member, chairman and interim president and CEO

TIAA Bank acquires $1.5 billion portfolio from GE Capital's HEF business Portfolio of healthcare equipment leases and loans

US hospital settles lawsuit over radiology services out of court Accused of trying to monopolize radiology services

How hassle maps can improve radiology department operations Tips for finding and addressing friction points and improving overall patient care in radiology

CMS to unveil mandatory payment model for radiation oncology Part of determining approach that saves more and offers greater quality

When radiologists speak up, follow-up imaging improves Study supports better communication between radiologists and referring clinicians

Deborah Conrad Grand Rounds hires former Intel CMO as chief marketing officer

Allstate Insurance files complaint against Long Island radiology practice Accused of submitting fraudulent charges of over $1 million

Radiology Partners scales reach with close to 30 additional sites Servicing 750 clients across 17 states

Anthem pays HHS $16 million over 'largest health data breach in US history'

by Thomas Dworetzky , Contributing Reporter
Anthem has agreed to pay $16 million to the U.S. Department of Health and Human Services, Office for Civil Rights (OCR) and take “major corrective action” over the massive 2015 electronic health records hack against it that exposed the private information of nearly 79 million people.

“The largest health data breach in U.S. history fully merits the largest HIPAA settlement in history,” said OCR director Roger Severino in a statement, adding, “Unfortunately, Anthem failed to implement appropriate measures for detecting hackers who had gained access to their system to harvest passwords and steal people’s private information.”

Story Continues Below Advertisement

THE (LEADER) IN MEDICAL IMAGING TECHNOLOGY SINCE 1982. SALES-SERVICE-REPAIR

Special-Pricing Available on Medical Displays, Patient Monitors, Recorders, Printers, Media, Ultrasound Machines, and Cameras.This includes Top Brands such as SONY, BARCO, NDS, NEC, LG, EDAN, EIZO, ELO, FSN, PANASONIC, MITSUBISHI, OLYMPUS, & WIDE.



The $16 million settlement eclipsed the previous high of $5.55 million paid to OCR in 2016.

The company reported the breach on March 13, 2015, revealing that hackers had breached its security on January 29, 2015, by using what is called an advanced persistent threat attack.

After the initial report, it was learned that the cyberattackers had used spear phishing emails to one of its subsidiaries and that at least one employee had been suckered into responding – which opened the way for additional attacks.

OCR determined that between December 2, 2014 and January 27, 2015, the hackers made off with the protected data, including names, social security numbers, medical ID numbers, addresses, dates of birth, email addresses, and employment information.

“We know that large healthcare entities are attractive targets for hackers, which is why they are expected to have strong password policies and to monitor and respond to security incidents in a timely fashion or risk enforcement by OCR,” said Severino.

Part of the Anthem punishment is because the firm also failed “to conduct an enterprise-wide risk analysis, had insufficient procedures to regularly review information system activity, failed to identify and respond to suspected or known security incidents, and failed to implement adequate minimum access controls to prevent the cyberattackers from accessing sensitive electronic protected health information (ePHI),” said the federal agency.

If Anthem fails to follow the corrective action plan laid out by OCR, and “and fails to curb the breach,” however, the agreement is off, according to the terms of the deal.

In June, 2017, Anthem agreed to a $115 million settlement of a lawsuit stemming from the breach.

The money represented the biggest data-breach settlement to date, according to a statement from the court-appointed plaintiff attorneys from Altshuler Berzon, Cohen Milstein, Girard Gibbs, and Lieff Cabraser.

“After two years of intensive litigation and hard work by the parties, we are pleased that consumers who were affected by this data breach will be protected going forward, and compensated for past losses,” said Eve Cervantez, co-lead counsel representing the plaintiffs in the Anthem litigation, at the time.

The agreement was given final approval on August 18.

The proposed deal also requires “Anthem to guarantee a certain level of funding for information security and to implement or maintain numerous specific changes to its data security systems, including encryption of certain information and archiving sensitive data with strict access controls.”

“We are very satisfied that the settlement is a great result for those affected and look forward to working through the settlement approval process,” said Andrew Friedman, co-lead plaintiffs’ counsel, at the time.

U.S. Healthcare Homepage


You Must Be Logged In To Post A Comment

Advertise
Increase Your
Brand Awareness
Auctions + Private Sales
Get The
Best Price
Buy Equipment/Parts
Find The
Lowest Price
Daily News
Read The
Latest News
Directory
Browse All
DOTmed Users
Ethics on DOTmed
View Our
Ethics Program
Gold Parts Vendor Program
Receive PH
Requests
Gold Service Dealer Program
Receive RFP/PS
Requests
Healthcare Providers
See all
HCP Tools
Jobs/Training
Find/Fill
A Job
Parts Hunter +EasyPay
Get Parts
Quotes
Recently Certified
View Recently
Certified Users
Recently Rated
View Recently
Certified Users
Rental Central
Rent Equipment
For Less
Sell Equipment/Parts
Get The
Most Money
Service Technicians Forum
Find Help
And Advice
Simple RFP
Get Equipment
Quotes
Virtual Trade Show
Find Service
For Equipment
Access and use of this site is subject to the terms and conditions of our LEGAL NOTICE & PRIVACY NOTICE
Property of and Proprietary to DOTmed.com, Inc. Copyright ©2001-2018 DOTmed.com, Inc.
ALL RIGHTS RESERVED