Compliance · · 3 min read

Ambry Genetics agrees to $700,000 HIPAA settlement

Ambry Genetics will pay $700,000 and follow a two-year corrective plan after an investigation into a phishing-related breach affecting 225,370 people.

Ambry Genetics has agreed to pay $700,000 to resolve alleged violations of federal health privacy rules after a phishing attack exposed the electronic protected health information of 225,370 people, according to HIPAA Journal.

The Aliso Viejo, California-based genetic testing and clinical genomics company reached the settlement with the U.S. Department of Health and Human Services’ Office for Civil Rights (OCR). Alongside the payment, Ambry Genetics must carry out a corrective action plan designed to address weaknesses identified during the agency’s investigation.

The company will remain under OCR monitoring for two years. The settlement follows an investigation into whether Ambry Genetics complied with requirements under the Health Insurance Portability and Accountability Act, commonly known as HIPAA.

How the breach happened

Ambry Genetics detected unusual activity in its email system on January 22, 2020. A subsequent forensic review found that an unauthorized person had entered an employee’s email account after the employee responded to a phishing message.

The criminal actor had access to the account from January 22 through January 24. Information potentially exposed during that period included names, addresses, dates of birth, driver’s license numbers, diagnoses or other condition details, medications, treatment information and some Social Security numbers.

Ambry Genetics reported the incident to OCR on March 22, 2020. Its initial report covered 232,772 people, but the company later revised the affected population to 225,370.

OCR opens investigations into breaches involving at least 500 people. In this case, the agency said its review found that Ambry Genetics had not completed an accurate and comprehensive assessment of threats and weaknesses involving the confidentiality, integrity and availability of electronic protected health information.

The agency also identified shortcomings in access controls. Ambry Genetics had not established policies and procedures to end access to electronic protected health information when workers left the company or no longer needed that access. In addition, unique usernames had not been provided to every workforce member who required access, limiting the ability to identify users and track their activity within relevant systems.

What the corrective plan requires

Under the agreement, Ambry Genetics must conduct a comprehensive risk analysis and create a risk-management programme based on the weaknesses it finds. The programme is intended to reduce or control those risks.

The company must also develop and apply policies and procedures intended to meet the HIPAA Security Rule and other HIPAA requirements. Every workforce member must receive training on those policies and procedures.

Another requirement is the assignment of unique identification to all workforce members whose activity takes place in systems containing electronic protected health information. That identification must allow activity to be traced to individual users.

The settlement followed OCR’s notification that it had identified alleged HIPAA violations and planned to impose a financial penalty. Ambry Genetics accepted the agency’s offer to resolve the matter through an agreement that combines the payment with the corrective measures.

Wider financial and regulatory consequences

The federal penalty is not the only cost connected with the incident. Ambry Genetics also faced a class-action lawsuit arising from the breach and settled that litigation for $12.25 million.

OCR Director Paula M. Stannard said phishing remains a frequent route to breaches involving protected health information and can expose weaknesses in an organisation’s compliance with the HIPAA Security Rule. She identified risk analysis, risk management and implementation of the Security Rule as central elements of cybersecurity.

HIPAA Journal reports that the Ambry Genetics agreement is OCR’s 10th financial penalty this year for alleged HIPAA violations and its 188th penalty overall. Of the agency’s penalties during the year, all but one have involved failures connected with risk analysis.

OCR has collected $3,030,250 in HIPAA fines so far this year. The Ambry Genetics settlement therefore adds to a broader enforcement focus on whether organisations understand their information-security risks and take documented steps to manage them.

hipaadata breachcybersecurityphishinghealthcare compliancegenetic testing

Continue reading

Read this in another language