
The breach report by the DHSS indicated that the device may have contained Personal Health Information (PHI) from approximately 2,000 patients. Â The OCR’s investigation eventually determined that the DHSS had not addressed device and media encryption and controls, completed a risk analysis or security training, or implemented sufficient risk-management measures. Â In addition to the monetary settlement, the second largest so far in a HIPAA violation case and the first involving a state agency, the agreement requires the Alaska DHSS to review, revise, and maintain policies and procedures to ensure that it complies with the HIPAA Security Rule in the future, and a monitor will report regularly to the OCR on the agency’s compliance efforts.
The OCR has made it clear that public entities as well as private ones are expected to comply with their obligations under the HIPAA rules. Â Anyone utilizing Electronic Health Records (EHR) or medical billing systems such as Allscripts MyWay or McKesson Practice Choice needs to adhere strictly to HIPAA rules and safeguard PHI. Â Microwize Technology can offer guidance.
