Skip to main content

HIPAA NEWS – HIPAA Privacy Fine $4.3 Million

Clinics Failed to Provide Patients with Records Access . . .

For the first time, federal officials have issued a civil monetary penalty to a healthcare organization for violations of the HIPPA privacy rule. Cignet Health of Prince George’s County, Md., was fined $4.3 million for the violations that involved failing to provide 41 patients with access to their medical records and then failing to cooperate with federal investigators.

The individuals affected filed records access complaints with the HHS’ Office for Civil Rights between September 2008 and October 2009. The HIPAA privacy rule requires that a covered entity, such as a clinic or hospital, provide a patient with a copy of their records no later than 60 days after a request. HHS imposed a “civil monetary penalty” of $1.3 million for Cignet’s violation of this requirement.

HHS explained in a statement that Cignet refused to respond to OCR’s demands to produce the records and failed to cooperate with OCR’s investigations of the complaints and produce the records in response to a subpoena. OCR filed a petition to enforce its subpoena in a U.S. District Court and obtained a default judgment against Cignet on March 30, 2010. On April 7, 2010, Cignet produced the medical records to OCR, but otherwise made no efforts to resolve the complaints through informal means, HHS said.

Cignet failed to cooperate with OCR’s investigations from March 2009 to April 2010, constituting willful neglect to comply with the HIPAA privacy rule, according to HHS. HIPAA covered entities are required under law to cooperate with the department’s investigations. The fine for these violations was $3 million.