HHS’ Office for Civil Rights Settles HIPAA Investigation of Ambry Genetics for Security Rule Violations
ID: da5b83d6-288b-518c-a296-cbd3bc1c00a4
STIX ID: report--da5b83d6-288b-518c-a296-cbd3bc1c00a4
Feed Name: DataBreaches.Net
HHS OCR announced a settlement with Ambry Genetics after a January 2020 phishing compromise of an employee email that potentially exposed PHI for 225,370 individuals (including names, addresses, DOBs, some SSNs/driver's licenses, diagnoses, lab results and treatment info); OCR found failures in risk analysis, access termination, and unique user identification, resulting in a $700,000 payment and a two-year monitored corrective action plan requiring risk analysis, risk management, policy updates, unique user IDs, and workforce training.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
