Clinical Scorecard: HHS Office for Civil Rights Reaches Settlement with Ambry Genetics Over HIPAA Breach Linked to Phishing Incident Impacting 225,000 Patients
At a Glance
Category
Detail
Condition
HIPAA Compliance and Cybersecurity
Key Mechanisms
Phishing attack leading to breach of protected health information (PHI)
Target Population
Covered entities and business associates in healthcare
Care Setting
Healthcare organizations handling electronic protected health information (ePHI)
Key Highlights
Settlement reached with Ambry Genetics for potential HIPAA Security Rule violations
Phishing incident compromised PHI of approximately 225,370 individuals
Ambry agreed to a corrective action plan and paid $700,000 to OCR
OCR emphasizes the importance of risk analysis and management for cybersecurity
Training for workforce members on Security Rule policies is mandated
Guideline-Based Recommendations
Diagnosis
Identify and assess risks and vulnerabilities affecting ePHI
Management
Implement a risk management plan to address identified security risks
Monitoring & Follow-up
Conduct routine evaluations of information system activity and audit controls
Risks
Failure to perform comprehensive risk analysis and manage access to ePHI
Patient & Prescribing Data
Individuals whose PHI was compromised
N/A
Clinical Best Practices
Establish unique user identification for systems containing ePHI
Encrypt ePHI in transit and at rest when appropriate
Deliver regular HIPAA training tailored to workforce roles