government
Alaska Medicaid to pay $1.7 million HIPAA fine
NEWS IN BRIEF — Posted July 9, 2012
The Alaska Dept. of Health and Social Services, the state’s Medicaid agency, has agreed to pay the federal Dept. of Health and Human Services $1.7 million to settle possible violations of the Health Insurance Portability and Accountability Act’s security regulations. The state Medicaid agency also will implement safeguards for the protected electronic health information of its Medicaid beneficiaries.
According to HHS, this represents the first HIPAA enforcement action it has taken with a state Medicaid agency. In addition to the settlement amount, the agreement includes a corrective action plan that requires Alaska’s Medicaid agency to review, revise, and maintain policies and procedures to ensure compliance with the HIPAA rule.
In an investigation, the HHS Office for Civil Rights found that a portable electronic storage device that possibly contained protected information was stolen from the vehicle of a state Medicaid employee.
During the investigation, HHS determined that the Alaska Medicaid agency did not have adequate policies and procedures in place to safeguard the protected information. It also had not completed a risk analysis, implemented sufficient risk-management measures or device and media controls, completed security training for its work force, or addressed device and media encryption as required by HIPAA.
In a June 27 statement, William J. Streur, the Alaska health department’s commissioner, said the agreement was the result of possible security violations, not the confirmed loss of actual personal information of Alaskans. “We have absolutely no indication that Medicaid data or personal information was lost or at risk.” The agreement is not an admission of wrongdoing, but rather the only way for both parties to avoid costly and protracted litigation, he said.
Note: This item originally appeared at http://www.ama-assn.org/amednews/2012/07/09/gvbf0709.htm.












