Cookies help us display personalized product recommendations and ensure you have great shopping experience.

By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
SmartData CollectiveSmartData Collective
  • Analytics
    AnalyticsShow More
    predictive analytics risk management
    How Predictive Analytics Is Redefining Risk Management Across Industries
    7 Min Read
    data analytics and gold trading
    Data Analytics and the New Era of Gold Trading
    9 Min Read
    composable analytics
    How Composable Analytics Unlocks Modular Agility for Data Teams
    9 Min Read
    data mining to find the right poly bag makers
    Using Data Analytics to Choose the Best Poly Mailer Bags
    12 Min Read
    data analytics for pharmacy trends
    How Data Analytics Is Tracking Trends in the Pharmacy Industry
    5 Min Read
  • Big Data
  • BI
  • Exclusive
  • IT
  • Marketing
  • Software
Search
© 2008-25 SmartData Collective. All Rights Reserved.
Reading: HIPAA Violations Cost Health Insurer $1.7 Million: Lessons Learned
Share
Notification
Font ResizerAa
SmartData CollectiveSmartData Collective
Font ResizerAa
Search
  • About
  • Help
  • Privacy
Follow US
© 2008-23 SmartData Collective. All Rights Reserved.
SmartData Collective > Data Management > Best Practices > HIPAA Violations Cost Health Insurer $1.7 Million: Lessons Learned
Best PracticesData ManagementITPrivacySecurity

HIPAA Violations Cost Health Insurer $1.7 Million: Lessons Learned

onlinetech
onlinetech
4 Min Read
SHARE

Reuters reports that WellPoint, Inc., the second largest U.S. health insurer, has reached a $1.7 million settlement with the Dept. of Health and Human Services as result of a data breach that exposed over 600k health records. WellPoint’s online database was found to be problematic for a few different reasons, as outlined in their resolution agreement. Read on for possible technical and strategic security solutions you can employ in your organization to avoid a similar fate:

Reuters reports that WellPoint, Inc., the second largest U.S. health insurer, has reached a $1.7 million settlement with the Dept. of Health and Human Services as result of a data breach that exposed over 600k health records. WellPoint’s online database was found to be problematic for a few different reasons, as outlined in their resolution agreement. Read on for possible technical and strategic security solutions you can employ in your organization to avoid a similar fate:

Problem 1:
Lacking technical safeguards to verify the person or entity seeking access to ePHI (electronic protected health information) in their database.

Solution:
Wherever ePHI exists, technical security services should be employed for authentication and authorization purposes. One way to do this is to keep ePHI on secure servers, in secure, HIPAA compliant data centers, and use two-factor authentication for VPN access. Limited access should be allowed only for certain users with unique IDs.

More Read

From the Midfield to the Top
Artificial Intelligence in InfoSec is Smarter Than You Think
State Secrets Laws Inhibit Open Data
5 Important Ways Artificial Intelligence Improves Sales
AI Advances Minimize Risk of Site Accessibility Lawsuits in eCommerce

Two-Factor Authentication

Problem 2:
Inadequate policies and procedures authorizing access to their online application database.

Solution:
For the HIPAA Security Rule, policies and procedures are key to maintaining administrative security within a healthcare or business associate organization. Not only should your organization develop policies, but your risk management officer should also conduct staff training and enforce the policies regularly.

Problem 3:
Failed to perform an appropriate technical evaluation in response to a software upgrade to its IT systems.

Solution:
The HHS press release cautions healthcare organizations to have safeguards in place whenever systems upgrades are conducted by covered entities or their business associates. One way to ensure your business associates or their subcontractors have the technical, administrative and physical security in place to meet HIPAA compliance standards is to check their independent audit report against the OCR HIPAA Audit Protocol.

One example is with a HIPAA hosting provider that may support a HIPAA compliant cloud on which an online application is hosted – don’t trust sensitive patient data with hosting providers that don’t thoroughly understand the regulatory needs of the healthcare industry. Securing ePHI starts with vetting your business associates and subcontractors that store the data.

For more about HIPAA security, read our HIPAA Compliant Hosting white paper.

HIPAA Compliant Hosting White PaperThis white paper explores the impact of HITECH and HIPAA on data centers. It includes a description of a HIPAA compliant data center IT architecture, contractual requirements, benefits and risks of data center outsourcing, and vendor selection criteria.

References:
WellPoint Pays HHS $1.7 Million for Leaving Information Accessible Over Internet

The post HIPAA Violations Cost Health Insurer $1.7 Million: Lessons Learned appeared first on Managed Data Center News.

TAGGED:hipaaWellPoint
Share This Article
Facebook Pinterest LinkedIn
Share

Follow us on Facebook

Latest News

street address database
Why Data-Driven Companies Rely on Accurate Street Address Databases
Big Data Exclusive
predictive analytics risk management
How Predictive Analytics Is Redefining Risk Management Across Industries
Analytics Exclusive Predictive Analytics
data analytics and gold trading
Data Analytics and the New Era of Gold Trading
Analytics Big Data Exclusive
student learning AI
Advanced Degrees Still Matter in an AI-Driven Job Market
Artificial Intelligence Exclusive

Stay Connected

1.2kFollowersLike
33.7kFollowersFollow
222FollowersPin

You Might also Like

Safeguarding Patient Data in EHRs

5 Min Read
data privacy and HIPAA
Security

Data Analytics Solutions To HIPAA Compliance During Quarantine

6 Min Read
data security breach
Uncategorized

HIPAA in a HITECH World: HIPAA Violations on the Rise

19 Min Read

Nine Components of a HIPAA Risk Analysis

5 Min Read

SmartData Collective is one of the largest & trusted community covering technical content about Big Data, BI, Cloud, Analytics, Artificial Intelligence, IoT & more.

giveaway chatbots
How To Get An Award Winning Giveaway Bot
Big Data Chatbots Exclusive
AI and chatbots
Chatbots and SEO: How Can Chatbots Improve Your SEO Ranking?
Artificial Intelligence Chatbots Exclusive

Quick Link

  • About
  • Contact
  • Privacy
Follow US
© 2008-25 SmartData Collective. All Rights Reserved.
Go to mobile version
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?