WSGR logoWSGR logo
WSGR logo
  • Experience
  • People
  • Insights
  • About Us
  • Careers

  • Practice Areas
  • Industries

  • Corporate
  • Intellectual Property
  • Litigation
  • Patents and Innovations
  • Regulatory
  • Technology Transactions

  • Capital Markets
  • Corporate Governance
  • Corporate Life Sciences
  • Derivatives
  • Emerging Companies and Venture Capital
  • Employee Benefits and Compensation
  • Energy and Climate Solutions
  • Executive Advisory Program
  • Finance and Structured Finance
  • Fund Formation
  • Greater China
  • Mergers & Acquisitions
  • Private Equity
  • Public Company Representation
  • Real Estate
  • Restructuring
  • Shareholder Engagement and Activism
  • Tax
  • U.S. Expansion
  • Wealthtech

  • Special Purpose Acquisition Companies (SPACs)

  • Environmental, Social, and Governance

  • AI and Data Center Infrastructure
  • Energy Regulation and Competition
  • Project Development and M&A
  • Project Finance and Tax Credit Transactions
  • Sustainability and Decarbonization
  • Transportation Electrification

  • U.S. Expansion Library and Resources

  • Post-Grant Review
  • Trademark and Advertising

  • Antitrust Litigation
  • Arbitration
  • Board and Internal Investigations
  • Class Action Litigation
  • Commercial Litigation
  • Consumer Litigation
  • Corporate Governance Litigation
  • Employment Litigation
  • Executive Branch Updates
  • Government Investigations
  • Internet Strategy and Litigation
  • Patent Litigation
  • Securities Litigation
  • State Attorneys General
  • Supreme Court and Appellate Practice
  • Trade Secret Litigation
  • Trademark and Copyright Litigation
  • Trial
  • White Collar Crime

  • Advertising, Promotions, and Marketing
  • Antitrust and Competition
  • Committee on Foreign Investment in the U.S. (CFIUS)
  • Communications
  • Data, Privacy, and Cybersecurity
  • Export Control and Sanctions
  • FCPA and Anti-Corruption
  • FDA Regulatory, Healthcare, and Consumer Products
  • Federal Trade Commission
  • Fintech and Financial Services
  • Government Contracts
  • National Security and Trade
  • Payments
  • State Attorneys General
  • Strategic Risk and Crisis Management
  • Tariffs, Customs, and Import Compliance

  • Antitrust and Intellectual Property
  • Antitrust Civil Enforcement
  • Antitrust Compliance and Business Strategy
  • Antitrust Criminal Enforcement
  • Antitrust Litigation
  • Antitrust Merger Clearance
  • European Competition Law
  • Third-Party Merger and Non-Merger Antitrust Representation

  • Anti-Money Laundering
  • Foreign Ownership, Control, or Influence (FOCI)
  • Team Telecom

  • AI in Healthcare
  • Animal Health
  • Artificial Intelligence and Machine Learning
  • Aviation
  • Biotech
  • Blockchain and Cryptocurrency
  • Clean Energy
  • Climate and Clean Technologies
  • Communications and Networking
  • Consumer Products and Services
  • Data Storage and Cloud
  • Defense Tech
  • Diagnostics, Life Science Tools, and Deep Tech
  • Digital Health
  • Digital Media and Entertainment
  • Electronic Gaming
  • Fintech and Financial Services
  • FoodTech and AgTech
  • Global Generics
  • Internet
  • Life Sciences
  • Medical Devices
  • Mobile Devices
  • Mobility
  • NewSpace
  • Quantum Computing
  • Semiconductors
  • Software

  • Offices
  • Country Desks
  • Events
  • Community
  • Our Diversity
  • Sustainability
  • Our Values
  • Board of Directors
  • Management Team

  • Austin
  • Boston
  • Boulder
  • Brussels
  • Century City
  • Hong Kong
  • London
  • Los Angeles
  • New York
  • Palo Alto
  • Salt Lake City
  • San Diego
  • San Francisco
  • Seattle
  • Shanghai
  • Washington, D.C.
  • Wilmington, DE

  • Law Students
  • Judicial Clerks
  • Experienced Attorneys
  • Patent Agents
  • Business Professionals
  • Alternative Legal Careers
  • Contact Recruiting
HHS Brings Landmark HIPAA Enforcement Action Against a Business Associate for Alleged Data Security Failures
Alerts
July 7, 2016

On June 29, 2016, the U.S. Department of Health and Human Services (HHS) announced a Resolution Agreement with Catholic Health Care Services of the Archdiocese of Philadelphia (CHCS), settling charges that CHCS failed to comply with the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Security Rule.1As part of the settlement, CHCS will pay $650,000 and must implement a corrective action plan (CAP).

Background

CHCS provides management and information technology services to six skilled nursing facilities and, as such, is considered a "business associate" under HIPAA. Business associates, which are organizations that provide certain types of services to HIPAA-covered entities, must comply with the HIPAA Security Rule. According to HHS, CHCS violated the Security Rule by failing to conduct an accurate and thorough assessment of the potential security risks to the electronic protected health information it held. HHS alleged that CHCS also failed to implement appropriate measures to reduce these risks to a reasonable and appropriate level. HHS initiated its investigation after receiving notice from the nursing homes that a CHCS mobile device was stolen. Protected health information of 412 individuals was stored on the device and, according to HHS, the device was not encrypted or password-protected.

CAP Requirements

In addition to the $650,000 payment, CHCS is required to conduct an initial and annual data security risk assessment and document the security measures it has implemented to sufficiently reduce any identified risks. CHCS must also develop the written policies, procedures, and training required by the Security Rule, provide them to HHS for review and approval, revise them as requested by HHS, and implement the revised policies, procedures, and training.2CHCS is required to provide the updated policies, procedures, and training to all workforce members and obtain their compliance certification.

To help ensure continued HIPAA compliance, HHS will monitor CHCS's compliance with these CAP requirements for two years. CHCS will need to update its policies and procedures at least annually and provide those updated policies to HHS for review. CHCS must also notify HHS of any workforce noncompliance with its HIPAA-related policies and procedures.

Implications

Since the release of the HIPAA Final Omnibus Rule in early 2013, HHS has held business associates directly responsible for complying with certain HIPAA requirements, including the Security Rule. Although HHS has been slow to bring enforcement actions against business associates, the agency has taken several steps—in addition to this enforcement action against CHCS—signaling much more interest in compliance by business associates.

Earlier this year, HHS highlighted the importance of business associate agreements (BAAs) in two enforcement actions against HIPAA-covered entities (e.g., health care providers, health plans, and health care clearinghouses).3For example, in its investigation of Raleigh Orthopaedic Clinic, HHS found that the clinic provided protected health information for approximately 17,300 patients to a business associate without a BAA in place. HHS stated that the lack of a BAA meant that sensitive health information was left without certain safeguards and vulnerable to misuse or improper disclosure.

In addition, in March 2016, HHS launched its HIPAA-compliance audit program of covered entities and business associates.4HHS will first perform desk audits of randomly selected covered entities and expects to perform desk audits of randomly selected business associates thereafter.5

In response to these initiatives, business associates should assess their HIPAA compliance efforts and update their compliance policies and procedures as needed. Doing so sooner rather than later is important, as HHS has indicated that it will require prompt responses to its requests made during its audits—according to HHS, organizations must respond to HHS within 10 business days of its document requests.6

Wilson Sonsini routinely helps HIPAA business associates with privacy and data security matters, including HIPAA Security Rule compliance and other HIPAA-related issues. For more information, please contact Lydia Parnes or another member of the firm's privacy and cybersecurity practice.


1The press release and settlement agreement are available at http://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/agreements/catholic-health-care-services/index.html.
2The policies must, at minimum, cover the following topics: encryption of electronic protected health information, password management, security incident response, mobile device controls, information system review, security reminders, log-in monitoring, data backup, disaster recovery, emergency mode operation, testing and revising of contingency plans, application and data criticality analysis, automatic log off, audit controls, and integrity controls.
3See the two settlements at http://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/agreements/raleigh-orthopaedic-clinic/index.html and http://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/agreements/north-memorial-health-care/index.html.
4See "No More Crying Wolf—HIPAA Audits Coming in 2016," The Wilson Sonsini Data Advisor, November 2015, https://www.wsgr.com/publications/PDFSearch/the-data-advisor/Nov2015/#8.
5For more information about the audit program, see http://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/audit/index.html#program.
6See more information about the HIPAA audits at http://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/audit/#timeline.

Contributors

  • Lydia B. Parnes
  • people
  • insights
  • about us
  • careers
  • Binder
  • Alumni
  • Mailing List Signup
  • Client FTP Portal
  • Privacy Policy
  • Terms of Use
  • Accessibility
WSGR logo
Twitter
LinkedIn
Facebook
Instagram
Youtube
Copyright © 2026 Wilson Sonsini Goodrich & Rosati. All Rights Reserved.