Events Calendar

Mon
Tue
Wed
Thu
Fri
Sat
Sun
M
T
W
T
F
S
S
26
27
28
29
30
31
2
3
4
5
6
7
8
9
10
8:30 AM - HIMSS Europe
11
12
13
14
15
16
17
18
19
20
21
22
26
27
28
29
1
2
3
4
5
6
e-Health 2025 Conference and Tradeshow
2025-06-01 - 2025-06-03    
10:00 am - 5:00 pm
The 2025 e-Health Conference provides an exciting opportunity to hear from your peers and engage with MEDITECH.
HIMSS Europe
2025-06-10 - 2025-06-12    
8:30 am - 5:00 pm
Transforming Healthcare in Paris From June 10-12, 2025, the HIMSS European Health Conference & Exhibition will convene in Paris to bring together Europe’s foremost health [...]
38th World Congress on  Pharmacology
2025-06-23 - 2025-06-24    
11:00 am - 4:00 pm
About the Conference Conference Series cordially invites participants from around the world to attend the 38th World Congress on Pharmacology, scheduled for June 23-24, 2025 [...]
2025 Clinical Informatics Symposium
2025-06-24 - 2025-06-25    
11:00 am - 4:00 pm
Virtual Event June 24th - 25th Explore the agenda for MEDITECH's 2025 Clinical Informatics Symposium. Embrace the future of healthcare at MEDITECH’s 2025 Clinical Informatics [...]
International Healthcare Medical Device Exhibition
2025-06-25 - 2025-06-27    
8:30 am - 5:00 pm
Japan Health will gather over 400 innovative healthcare companies from Japan and overseas, offering a unique opportunity to experience cutting-edge solutions and connect directly with [...]
Electronic Medical Records Boot Camp
2025-06-30 - 2025-07-01    
10:30 am - 5:30 pm
The Electronic Medical Records Boot Camp is a two-day intensive boot camp of seminars and hands-on analytical sessions to provide an overview of electronic health [...]
Events on 2025-06-01
Events on 2025-06-10
HIMSS Europe
10 Jun 25
France
Events on 2025-06-23
38th World Congress on  Pharmacology
23 Jun 25
Paris, France
Events on 2025-06-24
Events on 2025-06-25
International Healthcare Medical Device Exhibition
25 Jun 25
Suminoe-Ku, Osaka 559-0034
Events on 2025-06-30
Latest News

May 10: Hospitals fined $4.8M for HIPAA violation

patients
New York-Presbyterian Hospital and Columbia University Medical Center together on May 7 have agreed to hand over a whopping $4.8 million to settle alleged HIPAA violations after the electronic protected health information of 6,800 patients wound up on Google back in 2010.
Following an investigation by the Office for Civil Rights, the HHS division responsible for HIPAA enforcement, it was discovered that the HIPAA breach transpired when a CU physician, who developed applications for NYP and CU, attempted to deactivate a personally-owned computer server on the network containing ePHI. Due to lack of technical safeguards, server deactivation resulted in ePHI being accessible on the Internet.
The data was so widely accessible online that the entities learned of the breach after receiving a complaint by an individual who saw the ePHI of their deceased partner, a former NYP patient, online.
NYP will pay the lion’s share of the settlement at $3.3 million, while CU has agreed to pay $1.5 million.
Despite the more than $25.1 million in fines OCR has levied on healthcare entities that have demonstrated willful neglect over protecting patients’ health information, the cases involving disabled or nonexistent firewalls, unencrypted devices, emails sent with patient data to the wrong recipient, or accidentally posting PHI online are in no short supply.
Just last month, OCR levied nearly $2 million in fines against Concentra Health Services and Arkansas-based QCA Health Plan after two unencrypted laptops containing patient health information were stolen. Both entities also failed to implement proper risk analyses, according to OCR officials.
Not only do organizations face considerable federal and state penalties for violating privacy laws, there’s also all the associated costs that run up the bill.
These costs include extending free credit monitoring to patients, outsourcing hotline support, hiring an external investigation or forensic experts. Then, don’t forget the in-house investigations, legal costs and the hit to your reputation. All in all, these costs average to $2 million for each healthcare entity over a two-year period, according to a 2014 Ponemon Institute breach report.
It’s not all bad news, however. Some healthcare groups appear to be making modest improvements. The same Ponemon report highlighted a slight downtick in the number of breaches healthcare organizations reported in 2013, compared with 2012. In 2012, some 45 percent of healthcare organizations reported having a five or more data breaches. This past year, the number fell to 38 percent.
Source