This website and our authorized third-party service providers use cookies to achieve the purposes described in our Privacy Policy. If you would like to learn more or withdraw your consent to some or all cookies, please review our Privacy Policy. By selecting “I ACCEPT” on this banner, scrolling this page, clicking any link, or continuing to browse this site, you agree to the use of cookies.
Advocate Health Care Network (Advocate) has agreed to a settlement with the Department of Health and Human Services (HHS), Office for Civil Rights (OCR), for multiple potential violations of the Health Insurance Portability and Accountability Act (HIPAA) involving electronic protected health information (ePHI).
Advocate has agreed to pay a settlement amount of $5.55 million and adopt a corrective action plan. This significant settlement, the largest to-date against a single entity, is a result of the extent and duration of the alleged noncompliance (dating back to the inception of the Security Rule in some instances), the involvement of the State Attorney General in a corresponding investigation, and the large number of individuals whose information was affected by Advocate, one of the largest health systems in the country.
“We hope this settlement sends a strong message to covered entities that they must engage in a comprehensive risk analysis and risk management to ensure that individuals’ ePHI is secure,” said OCR Director Jocelyn Samuels. “This includes implementing physical, technical, and administrative security measures sufficient to reduce the risks to ePHI in all physical locations and on all portable devices to a reasonable and appropriate level.”
OCR began its investigation in 2013, when Advocate submitted three breach notification reports pertaining to separate and distinct incidents involving its subsidiary, Advocate Medical Group ("AMG"). The combined breaches affected the ePHI of approximately 4 million individuals.