-
1
Ambry Genetics settled with HHS OCR over a HIPAA breach affecting 225,370 patients due to a phishing attack in January 2020.
-
2
The breach involved compromised protected health information, including names, Social Security numbers, and medical records.
-
3
HHS OCR found Ambry violated HIPAA Security Rule provisions, including inadequate risk analysis and user access management.
-
4
As part of the settlement, Ambry agreed to a corrective action plan and paid $700,000, with OCR monitoring for two years.
-
5
OCR emphasizes the importance of risk management and cybersecurity measures to protect electronic protected health information.