Skip to content Skip to navigation

BCBS Puerto Rico Affiliate Hit with $3.5M HIPAA Fine

December 1, 2015
by Rajiv Leventhal
| Reprints

Triple-S Management Corporation, a Puerto Rico-based insurance holding company affiliated with Blue Cross and Blue Shield, has agreed to complete a Health Insurance Portability and Accountability Act (HIPAA) compliance corrective action program and pay a $3.5 million fine for HIPAA violations dating back to 2010.

Reports say that the fine is the second largest one paid to the U.S. Department of Health and Human Services’ (HHS) Office for Civil Rights (OCR) for a failure to protect patient information. It’s second only to when the New York and Presbyterian Hospital (NYP) and Columbia University (CU), which participate in a joint arrangement in which CU faculty members serve as attending physicians at NYP, paid out $4.8 million to OCR last year for failing to secure thousands of patients’ electronic protected health information (ePHI) held on their network, resulting in ePHI being accessible on Internet search engines.

On several occasions over the last few years, Triple-S let PHI, including names, address and health insurance claim numbers be leaked, and printed on the outside of pamphlets mailed to beneficiaries. The violations started in 2010, however, when two former Triple-S workforce members employed by a competitor improperly accessed restricted areas of Triple-S’s database. As a result, the ePHI accessed in the database included members’ names, contract numbers, home addresses, diagnostic codes and treatment codes, according to the resolution agreement.

After receiving multiple breach notifications from Triple-S involving unsecured protected health information, OCR initiated investigations to ascertain the entities’ compliance with HIPAA rules. OCR’s investigations indicated widespread non-compliance throughout the various subsidiaries of Triple-S, including:

  • Failure to implement appropriate administrative, physical, and technical safeguards to protect the privacy of its beneficiaries’ PHI
  • Impermissible disclosure of its beneficiaries’ PHI to an outside vendor with which it did not have an appropriate business associate agreement
  • Use or disclosure of more PHI than was necessary to carry out mailings
  • Failure to conduct an accurate and thorough risk analysis that incorporates all IT equipment, applications, and data systems utilizing ePHI
  • Failure to implement security measures sufficient to reduce the risks and vulnerabilities to its ePHI to a reasonable and appropriate level

“OCR remains committed to strong enforcement of the HIPAA rules,” OCR Director Jocelyn Samuels, said in a press release statement. “This case sends an important message for HIPAA covered entities not only about compliance with the requirements of the security rule, including risk analysis, but compliance with the requirements of the privacy rule, including those addressing business associate agreements and the minimum necessary use of protected health information.”

The settlement requires Triple-S to establish a comprehensive compliance program designed to protect the security, confidentiality, and integrity of the personal information it collects from its beneficiaries. Triple-S, with the help of OCR through its technical assistance, had already begun to take extensive corrective action, HHS said. 



ONC National Coordinator Gets Live Look at Carequality Data Exchange

Officials from Carequality have stated that there are now more than 150,000 clinicians across 11,000 clinics and 500 hospitals live on its network. These participants are also able to share health data records with one another, regardless of technology vendor.

American Red Cross, Teladoc to Provide Telehealth Services to Disaster Victims

The American Red Cross announced a partnership with Teladoc to deliver remote medical care to communities in the United States that are significantly affected by disasters.

Report: The Business of Cybercrime in Healthcare is Growing

While stolen financial data still has a higher market value than stolen medical records, as financial data can be monetized faster, there are indications that there is ongoing development of a market for stolen medical data, according to an Intel Security McAfee Labs report.

Phishing Attack at Baystate Health Potentially Exposes Data of 13K Patients

A phishing scam at Baystate Health in Springfield, Mass. has potentially exposed the personal data of 13,000 patients, according to a privacy statement from the patient care organization and a report from MassLive.

New Use Cases Driving Growth in Health Data Exchange through Direct

In an update, DirectTrust reported significant growth in Direct exchange of health information and the number of trusted Direct addressed enabled to share personal health information (PHI) in the third quarter of 2016.

Insurers to CBO: Consider Private Insurers’ Data in Evaluations of Telemedicine

Eleven private insurers, including Aetna, Humana and Anthem, are urging the Congressional Budget Office (CBO) to consider the experience of commercial insurers when evaluating the impact of telemedicine coverage in Medicare.