The US Department of Health and Human Services (HHS), Office for Civil Rights (OCR) announced a $548,265 civil monetary penalty against Children’s Hospital Colorado, concerning violations of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy and Security Rules following receipt of breach reports in 2017 and 2020, relating to email phishing and cyberattacks. OCR investigated Children’s Hospital Colorado following breaches which reported a phishing attack that compromised an email account containing 3,370 individuals’ PHI and another after three email accounts were breached, containing 10,840 individuals’ PHI.
OCR’s investigation determined that the first reported breach occurred because multi-factor authentication was disabled on an email account. The second breaches occurred, in part, when workforce members gave permission to unknown third parties to access their email accounts. OCR also found violations of the HIPAA Privacy Rule for failure to train workforce members on the HIPAA Privacy Rule, and the HIPAA Security Rule requirement to conduct a compliant risk analysis to determine the potential risks and vulnerabilities to ePHI in its systems. In June 2024, OCR issued a Notice of Proposed Determination seeking to impose a civil money penalty. Children’s Hospital Colorado waived its right to a hearing and did not contest OCR’s findings. Accordingly, OCR imposed a civil money penalty of $548,265.