UMass Amherst will pay a HIPAA fine after a workstation was infected with a malware program, which resulted in the disclosure of electronic protected health information, according to an article on the Campus Security website.
The settlement includes a corrective action plan and a payment of $650,000.
According to the U.S. Department of Health and Human Services, UMass failed to designate all of its healthcare components when hybridizing, incorrectly determining that while its University Health Services was a covered healthcare component, other components, including the location where the breach of ePHI occurred, were not covered components.
Because UMass failed to designate the location as a healthcare component, UMass did not implement policies and procedures at the center to ensure compliance with the HIPAA Privacy and Security Rules.
IAQ and Infection Mitigation: Plans Into Actions
Case Study: How NYU Langone Rebuilt for Resilience After Superstorm Sandy
Dayton Children's Hospital Announces New Rehabilitative Services Building
The Debate on Laundering Microfibers in Healthcare
Construction Begins for New Cancer Center at OhioHealth's Administrative Campus