preview

A Brief Note On Idaho State University ( Isu ) Essay

Decent Essays

Incident: Idaho State University (ISU) operates 29 outpatient clinics and is responsible for providing health information technology systems technology systems security at those clinics. Between four and eight of those ISU clinics are subject to the HIPAA Privacy and Security Rules, including the clinic where the breach occurred.
The HHS Office of Civil Rights (OCR) opened an investigation after ISU notified HHS of the breach in which the ePHI of approximately 17,500 patients was unsecured for at least 10 months, due to the disabling of firewall protections at servers maintained by ISU. OCR’s investigation indicated that ISU’s risk analyses and assessments of its clinics were incomplete and inadequately identified potential risks or vulnerabilities. ISU also failed to assess the likelihood of potential risks occurring.
OCR concluded that ISU did not apply proper security measures and policies to address risks to ePHI and did not have procedures for routine review of their information system in place, which could have detected the firewall breach much sooner.
On August 9, 2011, HHS received notification from ISU regarding a breach of its unsecured electronic protected health information (ePHI).
On November 22, 2011 HHS notified ISU of its investigation regarding ISU’s compliance with the Privacy, Security, and Breach Notification Rules. HHS’ investigation indicated that the following conduct occurred (“Covered Conduct”).
i. ISU did not conduct an analysis of the risk to the

Get Access