HHS Announces $1.5 Million HIPAA Settlement with Massachusetts Facilities
Time 2 Minute Read

On September 17, 2012, the Department of Health and Human Services (“HHS”) announced a $1.5 million settlement with the Massachusetts Eye and Ear Infirmary and Massachusetts Eye and Ear Associates Inc. (“MEEI”) for potential violations of the HIPAA Security Rule. In connection with the announcement, the HHS Office for Civil Rights (“OCR”) Director Leon Rodriguez stated that organizations should pay special attention to safeguarding information “stored and transported on portable devices such as laptops, tablets, and mobile phones” and that “compliance with the HIPAA Privacy and Security Rules must be prioritized by management and implemented throughout an organization, from top to bottom.”

The settlement relates to the theft of an unencrypted laptop containing electronic protected health information (“ePHI”) of MEEI patients and research subjects. Following the submission of a breach report to OCR as required by the Health Information Technology for Economic and Clinical Health (“HITECH”) Act, OCR began an investigation. As stated in the resolution agreement, OCR determined that MEEI had not complied with the requirements of the Security Rule, including by failing to (1) analyze the risks to e-PHI on an ongoing basis as part of its security management process, (2) implement security measures to ensure that the confidentiality of ePHI on portable devices was at a reasonable and appropriate level, (3) adopt security incident reporting and response procedures, (4) implement policies and procedures to restrict access to ePHI on portable devices to authorized users, (5) address the receipt and removal of portable devices from its facilities and (6) adopt technical measures to restrict access to ePHI on portable devices.

Pursuant to the resolution agreement, MEEI has agreed to pay $1.5 million to HHS in three annual installments of $500,000 to settle the potential violations. In addition, the Corrective Action Plan attached to the resolution agreement requires MEEI to develop HIPAA policies and procedures that focus on the risks and vulnerabilities of portable devices containing ePHI. Finally, MEEI is required to train its workforce on the new policies and procedures, conduct a risk analysis and designate a monitor who will report to OCR on MEEI’s compliance with the Corrective Action Plan.

View the Resolution Agreement.

You May Also Be Interested In

Time 2 Minute Read

The U.S. Department of Health and Human Services’ Office for Civil Rights recently announced a settlement with health care software company MMG Fusion to resolve the company’s alleged noncompliance with the HIPAA Privacy, Security and Breach Notification Rules.

Time 4 Minute Read

Recent changes to 42 CFR Part 2 mean many covered entities must update their HIPAA Notices of Privacy Practices by February 16, 2026.

Time 2 Minute Read

On March 5, 2026, the California Privacy Protection Agency announced that the agency had reached a settlement with Ford Motor Company resolving an enforcement action against the company that alleged noncompliance with the California Consumer Privacy Act’s opt-out of sale/sharing rights.

Time 2 Minute Read

In 2025, four states—California, Massachusetts, New York, and Washington—proposed fashion accountability bills. These bills would require high-earning entities in the fashion industry to conduct extensive supply chain due diligence, and to monitor and report greenhouse gas (GHG) emissions, water use, and chemical management.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page