Lahey Hospital and Medical Center Fined $850K for Potential HIPAA Security Violations | Healthcare Informatics Magazine | Health IT | Information Technology Skip to content Skip to navigation

Lahey Hospital and Medical Center Fined $850K for Potential HIPAA Security Violations

November 25, 2015
by Heather Landi
| Reprints

Burlington, Mass.-based Lahey Hospital and Medical Center this week agreed to pay $850,000 to settle potential  violations of the Health Insurance Portability and Accountability Act (HIPAA) Privacy and Security Rules stemming from a 2011 security breach.

The settlement was agreed upon with the U.S. Department of Health & Human Services Office for Civil Rights (OCR). In addition to the fines, Lahey Hospital will adopt a robust corrective action plan to correct deficiencies in its HIPAA compliance program. 

The potential violations stem from a security breach incident in October 2011 when Lahey Hospital reported that an unencrypted laptop used in connection with a computerized tomography (CT) scanner was stolen from the hospital’s radiology department, according to the HHS OCR resolution agreement. The laptop contained 599 patients’ electronic protected health information (ePHI).

According to an HHS OCR press release, the HIPAA settlement reinforces lessons for users of medical devices. As hospitals and health centers become more connected, it’s common for medical devices to be controlled and operated remotely, which poses certain security risks.

As a result of the security breach due to the laptop theft, OCR investigated Lahey Hospital’s compliance with HIPAA Rules and, according to the OCR resolution agreement, the agency found problems with the hospital’s security practices, such as failure to assign unique user names and a lack of physical safeguards to secure the laptop and restrict access to authorized users. According to the OCR, Lahey also failed to conduct an accurate and thorough analysis of the potential risks and vulnerabilities to the confidentiality, integrity and availability of its ePHI as part of its security management process and did not implement policies and procedures for the removal of hardware and electronic medic that contain ePHI into and out of its facility.

As part of the settlement, Lahey Hospital also will have to conduct an organization-wide risk analysis of the security risks and vulnerabilities to its ePHI and must submit the risk analysis and risk management plan to OCR.


Get the latest information on Health IT and attend other valuable sessions at this two-day Summit providing healthcare leaders with educational content, insightful debate and dialogue on the future of healthcare and technology.

Learn More



Study: Use of EHRs Does Not Reduce Administrative Costs

A recent study by Duke University and Harvard Business School researchers found that costs for processing a single bill ranged from $20 for a primary care visit to $215 for an inpatient surgical procedure, or up to 25 percent of revenue.

Kibbe to Step Down as CEO of DirectTrust

David Kibbe, M.D., M.B.A., announced he would step down as president and CEO of DirectTrust at the end of the year.

Sequoia Project Exec Appointed to HITAC’s Interoperability Task Force

The Sequoia Project’s CIO/CTO, Eric Heflin, has been appointed to the Health Information Technology Advisory Committee’s (HITAC) U.S. Core Data for Interoperability Task Force (USCDI).

Healthcare Orgs Report Improvements in Quality, Cost Using Data and Analytics

In 2017, nearly three dozen organizations ranging in size from small community hospitals to some of the nation’s largest integrated delivery systems documented 125 improvements in quality, cost and efficiency using technology and improvement processes.

Consortium to Promote Implementation of a FHIR Genomics Platform

At this week’s HL7 Genomics Conference in Washington, D.C., a new group was introduced to promote implementation of a FHIR Genomics platform.

Cedars-Sinai Collaborates on Organs-on-Chip Precision Medicine Project

Scientists at Los Angeles-based Cedars-Sinai, in partnership with biotechnology startup Emulate, are pioneering a Patient-on-a-Chip program to help predict which disease treatments would be most effective based on a patient's genetic makeup and disease variant.