To address possible noncompliance with the HIPAA Security Rule following a phishing incident at Ambry Genetics that potentially exposed the PHI of 225,370 individuals.
Approach:
Incident Identification: Ambry identified a phishing attack in January 2020 that compromised an employee’s email account, potentially exposing PHI of 225,370 individuals.
Investigation and Findings: The OCR investigated after Ambry's breach report in March 2020 and found violations of the HIPAA Security Rule.
Settlement Agreement: Ambry agreed to a corrective action plan and paid $700,000 to OCR.
Key Findings:
Ambry failed to perform an accurate, comprehensive risk analysis.
Procedures for terminating access to ePHI were not established.
Unique identifiers for user tracking in electronic systems were not assigned.
Interpretation:
OCR emphasizes the importance of risk analysis and management in preventing PHI breaches.
Limitations:
The article does not provide details on the specific corrective actions taken by Ambry post-settlement.
No information on the long-term effectiveness of the measures implemented.
Conclusion:
OCR continues to enforce HIPAA Rules to protect individuals' health information.