Spencer Gifts Resolves HIPAA Violations for $450,000 Financial Penalty
Spencer Gifts LLC has confirmed to pay a $450,000 financial penalty and implement a corrective action plan to take care of its alleged violations of the HIPAA Rules identified by the U.S. Department of Health and Human Services Office for Civil Rights (OCR) following an investigation into a ransomware-related data breach affecting its employer-sponsored group health plan covering 10,023 members.
The enforcement action stems from a November 2021 incident in which staff were unable to connect to the company’s virtual private network. An internal investigation determined the disruption was caused by a ransomware attack. A threat actor accessed Spencer Gifts’ network from November 24, 2021 to November 26, 2021, and encrypted files on systems that stored electronic protected health information (ePHI) using ransomware. The following data were compromised during the cyberattack: names, addresses, zip codes, phone numbers, email addresses, and Social Security numbers. The breach was reported to the OCR on January 24, 2022.
The OCR reviews reported breaches affecting 500 or more individuals to determine compliance with the HIPAA Rules. In this case, the agency identified deficiencies related to required safeguards under the HIPAA Security Rule, including the risk analysis requirement. Regulators stated that Spencer Gifts did not perform a HIPAA-compliant risk analysis and did not implement policies and procedures as required by the HIPAA Privacy Rule, HIPAA Security Rule, and HIPAA Breach Notification Rule under 45 C.F.R. § 164.316(a) and 45 C.F.R. § 164.530(i)(1).
Following its investigation, the OCR notified Spencer Gifts of its intent to impose a financial penalty. The organization was given the opportunity to resolve the matter through settlement. Spencer Gifts decided to pay $450,000 as penalty for the violation and to adopt a corrective action plan.
The corrective action plan requires the organization to conduct a comprehensive and accurate risk analysis, update HIPAA-related policies and procedures, distribute updated policies to its workforce, and update employees’ HIPAA training. The OCR stated that regulated entities, including covered group health plans, must ensure Security Rule safeguards are in place before a cyberattack occurs to protect ePHI.
This settlement is the 20th OCR investigation involving a ransomware attack that resulted in a financial penalty for HIPAA noncompliance. It is also the 14th enforcement action under the agency’s risk analysis enforcement initiative and the 7th HIPAA penalty announced this year. The OCR has collected $1,728,000 in penalties this year from three healthcare providers, two health plans, and two business associates related to HIPAA Rule violations.