Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

Two HIPAA settlement agreements illustrate need for encryption

By Mark Faccenda (US) on April 28, 2014
Email this postTweet this postLike this postShare this post on LinkedIn

On April 22, 2014, the US Department of Health and Human Services (“HHS”) Office of Civil Rights (“OCR”) announced that it had reached settlement agreements with two organizations alleged to have violated the Health Information Portability and Accountability Act of 1996 (“HIPAA”) in conjunction with the theft of unencrypted computers. HHS conducted a review of Concentra Health Services (“Concentra”) and QCA Health Plan, Inc of Arkansas (“QCA”), which had each provided HHS with notification of breach subsequent to those thefts.

HHS’s investigation into Concentra’s health data privacy practices concluded that “Concentra had previously recognized in multiple risk analyses that a lack of encryption on its laptops, desktop computers, medical equipment, tablets and other devices containing electronic protected health information (ePHI) was a critical risk. While steps were taken to begin encryption, Concentra’s efforts were incomplete and inconsistent over time leaving patient PHI vulnerable throughout the organization.”  Similarly, HHS investigated the QCA breach and concluded that “while QCA encrypted their devices following discovery of the breach, OCR’s investigation revealed that QCA failed to comply with multiple requirements of the HIPAA Privacy and Security Rules, beginning . . . in April 2005.”

Concentra agreed to pay $1,725,220 in relation to its settlement, and QCA agreed to pay $250,000. More information regarding these settlement agreements is available here. A copy of Concentra’s resolution agreement is available here; a copy of QCA’s resolution agreement is available here.

Photo of Mark Faccenda (US) Mark Faccenda (US)
Read more about Mark Faccenda (US)Email
  • Posted in:
    Health Care and Life Sciences, Privacy and Cybersecurity
  • Blog:
    Health Law Pulse
  • Organization:
    Norton Rose Fulbright
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo