HHS Imposes $3.2 Million in Civil Money Penalties for Failure to Encrypt | Practical Law
The Department of Health and Human Services (HHS) has announced the imposition of $3.2 million in civil money penalties against a large pediatric health care provider (a HIPAA covered entity) resulting in part from the provider's failure to take appropriate remedial measures in response to the impermissible disclosure of protected health information (PHI). The provider failed to request a hearing regarding HHS's proposed penalty determination, which the government has now finalized.