HHS’ Office for Civil Rights Settles Malicious Insider Cybersecurity Investigation for $4.75 Million
ID: 6253c10b-85f4-5f99-9647-d1d75317d6b6
STIX ID: report--6253c10b-85f4-5f99-9647-d1d75317d6b6
Feed Name: DataBreaches.Net
Threat Score
HHS OCR settled with Montefiore Medical Center for $4.75M over HIPAA Security Rule violations after an insider stole and sold ePHI of 12,517 patients, highlighting gaps in risk analysis, monitoring, and audit controls; the agreement mandates a corrective action plan, workforce training, and two years of oversight, while HHS reiterates broader cybersecurity guidance for the health sector.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
