Recent OCR Resolution Agreement and Corrective Action Plan ... Lessons LearnedResolution Agreement • October 15th, 2021
Contract Type FiledOctober 15th, 2021The Health and Human Services’ Office of Civil Rights (“OCR”) recently entered into yet another Resolution Agreement after investigating a serious breach incident involving the electronic protected health information (“e- PHI”) of over 2 million patients that was maintained by a Florida health care organization[1.] As with so many other past investigations, the OCR made findings that the organization lacked a thorough HIPAA security risk assessment and the necessary security measures and review procedures to safeguard the e-PHI maintained on the organization’s information system. Lastly, the OCR determined that the organization had disclosed PHI to third party vendors, acting as business associates, without obtaining satisfactory assurances by way of written business associate agreements.