Most Popular Stories
- CMS investigates hospital for harsh collections, EMTALA violation
- Temple, doc pay $1M to settle fraud claims
- Ex-hospital VP pleads guilty to bribery, kickbacks, theft
- Kinect works toward degree in early autism diagnosis
- Joplin hospitals share lessons on disaster planning
- High-volume hospitals are more costly for all patients
Events
- Digital Marketing: Everyone's Saying "Do It," Few Tell You What Works
- 2nd Annual Medical Devices Summit West
June 7-8, 2012 — DoubleTree by Hilton Hotel San Diego - Mission Valley San Diego, CA - 2nd Annual Medicare Advantage Compliance Symposium
May 31, 2012 — Washington Plaza Hotel, Washington, DC - IHI's Primary Care Practice Coach Program
Begins June 26, 2012
Paid Research Reports
- Electronic health records: getting it right first time
- Cloud Computing Adoption In The APAC Life Sciences Industry
- Stakeholder Opinions: Ophthalmology - Leading brands under threat
- Genomics, Proteomics and Metabolomics in Diagnostics: Market landscape, innovative technologies and future outlook
- Healthcare Regulatory Update: The United Arab Emirates
- Point of Care Testing: Evaluating the return to evidence based medicine, novel technologies and the competitive landscape
Free Newsletter
Free Newsletter
FierceHealthPayer provides the latest news about the fast-changing and heavily regulated area of healthcare reimbursement. Join 16,000 healthcare plan executives who get FierceHealthPayer via twice weekly email. Sign up today!
Top Tags
Health Net pays $55K fine for data breach involving 1.5M people
Health Net will pay $55,000 to settle a complaint that it didn't inform customers in Vermont that their personal information was lost along with an unencrypted computer hard drive. The Connecticut-based insurer also must submit to a data-security audit and file reports with Vermont regarding its security programs for the next two years.
The case arose after the loss of a portable hard drive that contained protected health information, Social Security numbers and financial information of roughly 1.5 million people, including 525 Vermonters. Health Net discovered the drive was missing on May 14, 2009, but did not start notifying affected Vermont residents until more than six months later, notes the Insurance Journal.
When it did notify Vermont residents, Health Net told them that it believed their risk of harm was low because "the files on the missing drive were not saved in a format that can be easily accessible." However, according to the Vermont attorney general's office, the files on the unencrypted drive were in TIF format, which can be viewed using many types of freely available software.
The complaint and proposed settlement with Health Net and Health Net of the Northeast were both filed on Friday, the Associated Press reports. The complaint alleges that Health Net's six-month delay in notifying Vermont residents violates the Security Breach Notice Act, which requires data collectors notify affected individuals of security breaches "in the most expedient time possible and without unreasonable delay."
The complaint also alleges that Health Net violated HIPAA by failing to secure protected health information, and that the company violated the Consumer Fraud Act by misrepresenting the risk posed to affected individuals in the company's notice letters, according to the attorney general's office.
Since that data breach also jeopardized Connecticut members, the Connecticut Insurance Department fined Health Net and its affiliates $375,000 for putting customers' personal data at risk, reports the Hartford Business Journal.
To learn more:
- see the Associated Press article via Business Week
- check out the Hartford Business Journal piece
- read the Vermont Attorney General's press release
Related Articles:
Connecticut AG investigates WellPoint data breach, fines Health Net $250K
Unencrypted email implicated in Geisinger patient data breach
AvMed sued for data breach that affected 1.2 million people
Home
| Subscribe | Advertise | Mobile Edition | RSS |
Privacy
| Site Map
| EditorsTHE FIERCEMARKETS NETWORKFierceEnergy | FierceSmartGrid | FierceFinance | FierceFinanceIT | FierceComplianceIT | FierceHealthcare | FierceHealthFinance | FierceHealthIT | Hospital Impact | FierceMobileHealthcare | FierceHealthPayer | FiercePracticeManagement | FierceEMR | FierceCIO | FierceCIO:TechWatch | FierceContentManagement | FierceMobileIT | FierceGovernmentIT | FierceGovernment | FierceHomelandSecurity | FierceBiotech | FierceBiotech Research | FiercePharma | FierceVaccines | FierceBiotechIT | FiercePharma Manufacturing | FierceMedicalDevices | FierceDrugDelivery | FierceCRO | FierceIPTV | FierceOnlineVideo | FierceTelecom | FierceEnterpriseCommunications | FierceBroadbandWireless | FierceDeveloper | FierceMobileContent | FierceWireless | FierceWireless:Europe | FierceCable© 2012 FierceMarkets. All rights reserved. |
![]() |
