Perfection Not Required: Fifth Circuit Vacates HHS OCR $4.3 Million Penalty for Potential Data Breach Case

On January 14, the Fifth Circuit vacated the University of Texas M.D. Anderson Cancer Center’s (M.D. Anderson) $4.3 million fine for HIPAA violations arising from its loss of more than 35,000 individuals’ protected health information (PHI). Data Incidents and Agency Response - In 2012, an M.D. Anderson faculty member’s unencrypted laptop containing electronic protected health information (ePHI) for 29,021 individuals was stolen. Later in 2012, an M.D. Anderson trainee lost an unencrypted...
By: Bass, Berry & Sims PLC

Array