THE US Department of Health and Human Services’ Office for Civil Rights (OCR) has reached a $700,000 settlement with Ambry Genetics Corporation over potential violations of the HIPAA Security Rule. Ambry, a California-based provider of genetic testing and clinical genomics services, reported in March 2020 that an employee’s email account had been compromised in a phishing attack discovered in January that year.
The incident potentially exposed the protected health information of 225,370 people, including names, addresses, dates of birth, some Social Security or driving licence numbers, financial information, diagnoses, laboratory results, medications and treatment details.
OCR said Ambry may have failed to carry out an accurate and thorough risk analysis of threats to electronic protected health information; implement procedures to remove or restrict access when a worker’s access was no longer appropriate; and assign unique user names or numbers for identifying and tracking users of systems containing ePHI. The settlement does not state that all the listed information was exfiltrated, only that it was potentially accessed by the attacker.
Ambry has agreed to a corrective action plan monitored by OCR for two years. It must conduct a full risk analysis, create a risk-management plan, review and update Security Rule policies, introduce unique user identification across systems containing ePHI, and train its workforce on those policies.
OCR also urged regulated organisations to map where ePHI is stored and transferred, maintain audit controls, review system activity, use authentication and appropriate encryption, apply lessons from incidents, and provide role-specific HIPAA training.