No One Is Immune: OCR Holds State Medicaid Agency Accountable For HIPAA Compliance

The Office for Civil Rights (OCR) of the U.S. Department of Health and Human Services (HHS) has once again entered into a significant settlement evidencing its commitment to the aggressive enforcement of the Health Insurance Portability and Accountability Act (HIPAA) Security Rule. In its first HIPAA enforcement action against a state agency, HHS announced on June 26, 2012, that it had entered into a $1.7 million settlement as part of a resolution agreement with the Alaska Department of Health and Social Services (DHSS), the state's Medicaid agency. In addition to payment of the settlement, the resolution agreement requires DHSS to comply with a corrective action plan to properly safeguard the electronic protected health information (ePHI) of its Medicaid beneficiaries.

The resolution agreement resulted from an OCR investigation into the 2009 theft of a portable electronic storage device, which potentially contained ePHI, from the vehicle of a DHSS computer technician. As a result of the investigation, OCR determined that, in contravention of the requirements of the Security Rule, DHSS had failed to: (1) complete a risk analysis; (2) implement sufficient risk management measures; (3) implement device and media controls; and (4) address device and media encryption.

As part of the resolution agreement, DHSS entered into a corrective action plan, which requires DHSS to implement the following corrective actions:

Develop, maintain and revise as necessary its written policies and procedures relating to the deficiencies found in the investigation and distribute the policies and procedures to all members of the workforce who have access to ePHI. Required policies and procedures include, but are not limited to, procedures for: (a) tracking devices containing ePHI; (b) safeguarding devices containing ePHI; (c) encrypting devices containing ePHI; (d) disposal and/or re-use of devices that contain ePHI; (e) responding to security incidents; and (f) applying sanctions to workforce members who violate...

To continue reading

Request your trial

VLEX uses login cookies to provide you with a better browsing experience. If you click on 'Accept' or continue browsing this site we consider that you accept our cookie policy. ACCEPT