Judge Tosses Penalty Against Texas MD Anderson Cancer Center

$4.3 million penalty stemmed from two instances of lost, unencrypted USB drives containing patient data


The boom of information technology in healthcare has brought a host of benefits to patients, physicians and organizations. The expansion of technology has been especially evident as organizations have struggled through the COVID-19 pandemic have tried to remain accessible to patients. Embracing technology also comes with potential risks related to data security.

The U.S. Court of Appeals for the Fifth Circuit has vacated the $4.3 million civil monetary penalty against the University of Texas MD Anderson Cancer Center after two years and several lost appeals, according to Health IT Security. The penalty stemmed from two instances of lost, unencrypted USB drives containing patient data.

The judge ruled the decision by the U.S. Department of Health and Human Services to levy the massive fine against MD Anderson was “arbitrary, capricious, and contrary to law.” The highly publicized Office for Civil Rights settlement stemmed from two data breaches in 2012 and 2013. 

In the first instance, a criminal stole an unencrypted laptop that contained protected health information and research data in April 2012. The device contained the names, medical records numbers, treatments, research information, and some Social Security numbers, of about 29,201 patients.

Several months later, MD Anderson reported another data loss incident, where a trainee lost an unencrypted portable hard drive on a campus shuttle bus. Another unencrypted USB drive was lost in 2013, which also contained ePHI.

An OCR investigation found MD Anderson’s own risk analysis determined that its lack of device-level encryption posed a high risk to the privacy and security of the ePHI in its possession. Despite the risks, OCR alleged MD Anderson did not begin an enterprise-wide adoption of ePHI encryption until 2011.

Click here to read the article.



January 25, 2021


Topic Area: Information Technology


Recent Posts

Probiotic Cleaning: A Complementary Strategy for Safer Hospital Floors

Managers seeking more resilient approaches to environmental hygiene are turning to probiotic systems to supplement traditional disinfection.


VITAS Healthcare Breaks Ground on New Inpatient Hospice Center in Florida

The 14,000-square-foot VITAS inpatient hospice center will open in 2027 and serve 500+ patients annually.


Mile Bluff Medical Center Disrupted by Data Security Event

While some services experienced limited and temporary interruptions, the impact has been narrow in scope.


The Proper Way to Use Cleaning Carts

Environmental services use cleaning carts every day, but they are often overlooked. Keeping them clean and properly stocked is key to preventing infection in healthcare facilities.


JPS Health Network Breaks Ground on New Hospital

The project includes construction of a new inpatient hospital and expansion of the existing Pavilion.


 
 


FREE Newsletter Signup Form

News & Updates | Webcast Alerts
Building Technologies | & More!

 
 
 


All fields are required. This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

 
 
 
 

Healthcare Facilities Today membership includes free email newsletters from our facility-industry brands.

Facebook   Twitter   LinkedIn   Posts

Copyright © 2023 TradePress. All rights reserved.