UMass Amherst to pay $650,000 HIPAA fine

A workstation was infected with a malware program, which resulted in the disclosure of electronic protected health information


UMass Amherst will pay a HIPAA fine after a workstation was infected with a malware program, which resulted in the disclosure of electronic protected health information, according to an article on the Campus Security website.

The settlement includes a corrective action plan and a payment of $650,000.

According to the U.S. Department of Health and Human Services, UMass failed to designate all of its healthcare components when hybridizing, incorrectly determining that while its University Health Services was a covered healthcare component, other components, including the location where the breach of ePHI occurred, were not covered components.  

Because UMass failed to designate the location as a healthcare component, UMass did not implement policies and procedures at the center to ensure compliance with the HIPAA Privacy and Security Rules. 

Read the article.

 

 



December 8, 2016


Topic Area: Information Technology


Recent Posts

UF Health Hospitals Rely on Green Globes to Realize Their Full Potential

Case study: The process encouraged the team to push themselves in several areas.


How Healthcare Facilities Can Be Truly Disaster-Resilient

Real resilience looks different than what’s written down in plans


TriasMD Breaks Ground on DISC Surgery Center for San Fernando Valley

It is set to open in Q3 2025


Bigfork Valley Hospital Falls Victim to Data Breach

The incident occurred in November 2024


AI-Driven Facilities: Strategic Planning and Cost Management 

6 factors to ensure infrastructure, operations and financial management support AI’s integration


 
 


FREE Newsletter Signup Form

News & Updates | Webcast Alerts
Building Technologies | & More!

 
 
 


All fields are required. This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.