Ambry Genetics Corporation has decided to pay $700,000 to the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) and carry out a corrective action plan to settle potential HIPAA Security Rule violations discovered during an investigation of a phishing incident in 2020 impacting the protected health information (PHI) of 225,370 individuals.
In January 2020, Ambry found out that a phishing attack resulted in the compromise of an employee’s email account. The account was accessed from January 22 to January 24, 2020. The threat actor may have exfiltrated the PHI of 225,370 individuals. The breached information included names, addresses, birth dates, some driver’s license numbers or Social Security numbers, financial data, diagnoses and conditions, laboratory data results, prescription drugs, and treatment data.
Ambry Genetics reported the data breach to OCR on March 22, 2020, as impacting 232,772 individuals, but this figure was later updated to 225,370 individuals.
OCR Investigation Identified HIPAA Security Rule Issues
OCR started its investigation after Ambry Genetics submitted a data breach report with regards to the phishing incident. OCR discovered that Ambry Genetics had potentially violated terms of the HIPAA Security Rule.
The findings involved a failure to perform an accurate and detailed risk analysis of probable risks and vulnerabilities relating to electronic protected health information (ePHI) kept by Ambry Genetics.
OCR likewise discovered that Ambry Genetics had not enforced procedures for ending access to ePHI whenever a workforce member’s work or other contract ended or when access was not appropriate anymore.
A third finding was about user ID. Ambry Genetics failed to designate a unique name or number for determining and tracking user ID in electronic systems that contain ePHI.
Corrective Action Plan
With the resolution agreement, Ambry Genetics decided to pay $700,000 to OCR and use a corrective action plan that OCR will keep an eye on for two years.
The plan calls for Ambry Genetics to perform an accurate and detailed risk analysis dealing with potential risks and vulnerabilities to the integrity, confidentiality, and availability of its ePHI.
Ambry Genetics also consented to create and carry out a risk management plan responding to security risks and vulnerabilities discovered through the risk analysis.
The company needs to create, review, and modify its policies and procedures as necessary to comply with the HIPAA Rules. The plan likewise requires unique user ID in information systems that contain ePHI.
Workforce members need to get training concerning the company’s HIPAA Security Rule policies and procedures.
OCR Cybersecurity Measures
OCR identified several measures for covered entities to deal with cyber threats. These include determining where ePHI is located and knowing how that data enters, moves across, and leaves a company’s information systems.
OCR also found regular risk analysis and risk management, audit controls that log and confirm data system activity, regular checks of information system activity, and systems for authenticating data to make sure that only authorized users access ePHI.
OCR also recommended encryption of ePHI, incorporation of lessons discovered from incidents into security management methods, and regular HIPAA training personalized to workforce members and their job responsibilities.