University of California Settles HIPAA Privacy and Security Case involving UCLA Health System Facilities

New! Get Your HIPAA/HITECH Compliance Checklist PDF from The HIPAA Academy

Following an investigation by the Department of Health and Human Services (HHS) Office for Civil Rights (OCR), the University of California at Los Angeles Health System (UCLAHS) has agreed to settle potential violations of the HIPAA Privacy and Security Rules for $865,500 and has committed to a corrective action plan aimed at remedying gaps in its compliance with the rules.

The Resolution Agreement resolves two separate complaints filed with OCR on behalf of two celebrity patients who received care at UCLAHS. The complaints alleged that UCLAHS employees repeatedly and without permissible reason looked at the electronic protected health information of these patients.

OCR’s investigation into the complaints revealed that from 2005-2008, unauthorized employees repeatedly looked at the electronic protected health information of numerous other UCLAHS patients. Through policies and procedures, entities covered under HIPAA must reasonably restrict access to patient information to only those employees with a valid reason to view the information and must sanction any employee who is found to have violated these policies.

“Covered entities are responsible for the actions of their employees. This is why it is vital that trainings and meaningful policies and procedures, including audit trails, become part of the every day operations of any health care provider,” said OCR Director Georgina Verdugo. “Employees must clearly understand that casual review for personal interest of patients’ protected health information is unacceptable and against the law.”

The corrective action plan requires UCLAHS to implement Privacy and Security policies and procedures approved by OCR, to conduct regular and robust trainings for all UCLAHS employees who use protected health information, to sanction offending employees, and to designate an independent monitor who will assess UCLAHS compliance with the plan over 3 years.

“Covered entities need to realize that HIPAA privacy protections are real and OCR vigorously enforces those protections.  Entities will be held accountable for employees who access protected health information to satisfy their own personal curiosity,” said Director Verdugo. 

Complimentary - HIPAA & HITECH Compliance Checklist PDF
ecfirst, Home of The HIPAA Academy, has developed a comprehensive checklist for complying with HIPAA and the HITECH Act. Contact John at John.Schelewitz@ecfirst.com for your exclusive copy of the HIPAA Checklist PDF.

Learn more about  the Certified HIPAA Professional (CHP) and Certified Security Compliance Specialist (CSCS) Program scheduled to be delivered in Newark, California, August 2-5, 2011. Register today @ www.ecfirst.com.


About ecfirst
Devoted To Our Clients. Delivering with Passion.

ecfirst is a leader with rich hands-on experience delivering world-class services in the areas of:

  • Security regulatory compliance solutions (HIPAA, HITECH Act, PCI DSS, NIST and ISO 27000 Standards, State Regulations)
  • Compliance training and certification
  • HITECH data breach and incident response management
  • End-to-end Meaningful Use EHR Stage 1 objective driven services including gap assessment, risk analysis, reporting and more
  • Customized portal development and implementation for access to confidential client information
  • Professional staffing, including project management, HL7, HIPAA, ICD 9/10 and more
Graphic02.jpg

Regulatory Compliance Practice
The ecfirst Regulatory Compliance Practice delivers deep expertise with its full suite of services that include; HIPAA Privacy Gap Analysis, Meaningful Use Risk Analysis, HITECH Data Breach, Technical Vulnerability Assessment, Policy and Procedure Development, Disaster Recovery Planning, On-Demand Consulting, as well as managed security and IT infrastructure solutions.

Compliance and Training Certification
ecfirst, home of the HIPAA Academy, offers the gold standard in compliance training and certification.  The HIPAA CHATM and CHP certifications are the only certifications recognized in the Industry. The ecfirst Certified Security Compliance SpecialistTM (CSCSTM) Program is the first and only information security program that addresses all major compliance regulations from a security perspective.

ecfirst delivers world-class information security and regulatory compliance solutions. With over 1,600+ clients, ecfirst was recognized as an Inc. 500 business – America’s Top 500 Fastest Growing Privately Held Business in 2004 – our first year of eligibility. ecfirst serves a Who's Who client list that includes technology firms, numerous hospitals, state and county governments, and hundreds of businesses across the United States and abroad. A partial list of clients includes Microsoft, Symantec, HP, McKesson, EMC, IBM, Principal Financial, U.S. Army, U.S. Dept. of Homeland Security, U.S. Dept. of Veterans Affairs and many others. 

ecfirst Differentiators
ecfirst combines state of the art tools, the highest credentialed staff, and reporting that maximizes value, efficiency, and information for our clients to deliver the industry’s best technical vulnerability assessments. Critical ecfirst differentiators include:

  • Home of The HIPAA Academy – First in the healthcare industry with the Certified HIPAA Professional (CHP) and the Certified Security Compliance Specialist (CSCS) programs
  • Highly credentialed professional consulting team with expertise in HL7, ICD-9/10, HIPAA, HITECH, Meaningful Use
  • Deep experience in the healthcare industry
  • Compliance based vulnerability assessments
  • Executive dashboards that may be tailored for senior management to highlight critical findings

Have you conducted a HIPAA & HITECH risk analysis exercise?
Talk to ecfirst and you will find an organization that is passionate about the services we deliver and exceptionally devoted to its clients. We deliver value with intensity and are paranoid about our performance for your organization.

Contact ecfirst
Call John @ +1.480.663.3225 or email at John.Schelewitz@ecfirst.com. Talk to us about your security challenges and compliance priorities. We want to listen and tailor a solution specific to your requirements.