Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

Health Plan Settles HHS OCR Investigation Related to Photocopier Breach for $1.2M

By Lynn Sessions, Theodore J. Kobus III & King L. Wong, Ph.D. on August 22, 2013
Email this postTweet this postLike this postShare this post on LinkedIn

The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) recently announced its fourth resolution agreement of 2013. Affinity Health Plan, Inc., a nonprofit managed care plan serving the New York metropolitan area, has agreed to settle potential violations of the HIPAA Privacy and Security Rules for $1.2 million. The resolution agreement relates to Affinity’s April 15, 2010, report to OCR of an incident where Affinity was contacted by a representative of CBS Evening News regarding an investigative report that CBS had purchased a photocopier previously leased by Affinity on which the hard drive contained the confidential medical information of approximately 344,579 individuals.

On May 19, 2010, in response to Affinity’s report, OCR initiated its investigation into Affinity’s compliance with the Privacy, Security and Breach Notification Rules. OCR’s investigation indicated the following:

  • Affinity impermissibly disclosed electronic protected health information (ePHI) when it failed to properly erase photocopier hard drives prior to sending the photocopiers to a leasing company;
  • Affinity failed to assess and identify the security risks and vulnerabilities of ePHI stored in the photocopier hard drives; and
  • Affinity failed to implement its policies for the disposal of ePHI with respect to the photocopier hard drives.

In addition to the settlement amount, Affinity agreed to a 120-day corrective action plan that provides for the following:

  • Affinity will use its best efforts to retrieve all photocopier hard drives contained in photocopiers previously leased by Affinity that remain in the possession of the leasing agent and safeguard all ePHI contained therein from impermissible disclosure. Affinity must either provide documentation of best efforts or provide written certification that it has completed this requirement.
  • Affinity will conduct a comprehensive risk analysis of the ePHI security risks and vulnerabilities that includes all electronic equipment and systems controlled, owned or leased by Affinity. This risk analysis must be provided to OCR for review and recommended changes prior to implementation and training of Affinity staff.

Directly addressed in HHS’s press release regarding the Affinity settlement, HHS advises covered entities to be cognizant of the importance of safeguarding sensitive data, referring to FTC guidance, NIST guidance and OCR training. Sensitive data can be stored on devices beyond just laptops, thumb drives and external hard drives. As a result, determining whether there are other devices and equipment that may be storing ePHI that have not been previously considered should be part of your periodic risk assessment. With enforcement of the Final Rule beginning on September 23, 2013, liability for potential HIPAA violations, such as the above, also will extend directly to business associates that receive or store PHI.

Photo of Lynn Sessions Lynn Sessions
Read more about Lynn SessionsEmailLynn's Linkedin ProfileLynn's Twitter Profile
Photo of Theodore J. Kobus III Theodore J. Kobus III

Ted Kobus stands at the forefront of cyber protection — no small role in an era defined by crippling data breaches and daily digital threats. He has earned authority in the areas of privacy, data security and cybersecurity, leading clients to entrust him…

Ted Kobus stands at the forefront of cyber protection — no small role in an era defined by crippling data breaches and daily digital threats. He has earned authority in the areas of privacy, data security and cybersecurity, leading clients to entrust him with more than 6,000 data breach responses. Businesses, government and other organizations turn to Ted for sound advice on compliance, developing response strategies, breaches implicating domestic and international laws, and defense of both class action litigation and regulatory actions. Notably, he has developed key relationships with the U.S. Department of Justice (DOJ), where he and his team have helped to establish protocols to protect corporate victims following a data breach. He knows the most proactive regulators involved in this space and interacts with them regularly.

Ted has led the defense to hundreds of regulatory investigations, including those brought by the Attorney General Multi-State, Department of Health and Human Services Office for Civil Rights, Departments of Insurance, SEC and FTC. In the healthcare space, Ted has defended more than 200 OCR investigations and has negotiated more privacy/security-related resolution agreements than any other lawyer.

Ted is consistently ranked in Chambers USA: America’s Leading Lawyers for Business, and he is one of only a handful of attorneys nationwide named an MVP by Law360 for Privacy and Consumer Protection. He is a regular contributor to BakerHostetler’s Data Counsel blog, and he frequently speaks at major industry events regarding data breach response, risk management and litigation issues affecting privacy. Ted has spoken at the National Association of Attorneys General on data security issues in a closed session, as well as the National Security Cyber Specialist’s Training Conference organized by the DOJ.

Ted is the firmwide chair of BakerHostetler’s Digital Assets and Data Management Group and a member of the firm’s Policy Committee.

Read more about Theodore J. Kobus IIIEmailTheodore's Linkedin ProfileTheodore's Twitter Profile
Show more Show less
  • Posted in:
    Privacy and Cybersecurity
  • Blog:
    Health Law Update
  • Organization:
    Baker & Hostetler LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo