Holland & Hart's Health Law Blog
  • Publications
  • Webinar Recordings
    • 2026 Webinar Recordings
    • 2025 Webinar Recordings
    • 2024 Webinar Recordings
    • 2023 Webinar Recordings
    • 2022 Webinar Recordings
    • 2021 Webinar Recordings
    • 2020 Webinar Recordings
    • 2019 Webinar Recordings
    • 2018 Webinar Recordings
    • 2017 Webinar Recordings
    • 2016 Webinar Recordings
  • Compliance Bootcamps
  • Attorneys
  • Healthcare Law
  • Employers’ Lawyers Blog
  • Click to open the search input field Click to open the search input field Search
  • Menu Menu

Blog Article

CardioNet Settlement Shows Need for Healthcare Providers to Secure Mobile Devices

April 28, 2017/in HIPAA, Providers

By Kim Stanger

In the first Health Insurance Portability and Accountability Act (“HIPAA”) settlement involving a wireless health services provider, CardioNet on April 24 agreed to pay $2.5 million for allegedly losing a laptop containing individual health information.

The size of this and other recent settlements demonstrates the increasingly active stance being taken by the Department of Health and Human Services Office for Civil Rights (“OCR”) on the need for organizations to implement strong, HIPAA-compliant security policies – including those involving mobile devices used for work. The settlement was based on the impermissible disclosure of unsecured electronic protected health information (“ePHI”).

Pennsylvania-based CardioNet provides remote mobile monitoring and rapid response to patients at risk for cardiac arrhythmias. In 2012, the company reported to OCR that a workforce member’s unencrypted laptop had been stolen from a parked vehicle outside the employee’s home. The laptop contained the ePHI of 1,391 individuals.

Encryption Can Help

OCR’s investigation revealed that, at the time of the theft, CardioNet lacked sufficient risk analysis and risk management. In addition, the company’s policies and procedures implementing the standards of the HIPAA Security Rule were in draft form and had not been implemented.

Breaches such as this can be prevented by the use of encryption. If an encrypted device containing ePHI is lost or stolen, the incident does not need to be reported to OCR and patients do not need to be notified. Most importantly, patients’ ePHI will not be exposed if devices are lost or stolen. While encryption is not cheap, it is much less expensive than an OCR fine.

In addition to the fine, CardioNet agreed to adopt a corrective action plan requiring it to conduct a risk analysis, develop and implement a risk-management plan, revise its employee training program, and implement secure device and media controls.

A “Watershed Year”

In the past year, healthcare entities have seen a dramatic increase in HIPAA enforcement – and the related costs. CardioNet marks the seventh multi-million-dollar settlement with OCR in the last year – including a $5.5 million settlement with Memorial Healthcare System in February, a $2.14 million settlement with St. Joseph Health in October, a $5.5 million settlement with Advocate Healthcare in August, and $2.7 million settlements with Oregon Health & Science University and the University of Mississippi Medical Center in July.

And it is unlikely that this trend will change. A recent study issued by Navigant Global Technology Solutions indicates that 2017 is shaping up to be another “watershed year” for cybersecurity threats and attacks. Last year, healthcare accounted for by far the largest percentage of reported breaches – 42.7 percent.

This report suggests that organizations of all sizes partner with outside consultants and experts to ensure that all requirements are met and routinely audited. These actions include:

  • Establish a cybersecurity program;
  • Adopt a cybersecurity policy;
  • Identify and install a chief information security officer;
  • Establish a policy and process to assess vendor cybersecurity; and
  • Conduct an annual risk assessment to include penetration testing.

On May 19, Holland & Hart will offer a complementary Healthcare Compliance Bootcamp – which will include HIPAA updates as well as a segment on the latest trends at the intersection of cybersecurity law and the healthcare industry. Although this event will focus on Idaho law, the included information will address many aspects of the HIPAA privacy and security rules, and will be of use to entities in any jurisdiction. The event will be webcast.

For more information about how entities in the healthcare industry can protect themselves from breaches of HIPAA-protected information, sign up for our event, our webcast, or contact attorneys Kim Stanger and Matt Sorensen in Holland & Hart’s Boise and Salt Lake City offices.


For questions regarding this update, please contact:
Kim C. Stanger
Holland & Hart, 800 W Main Street, Suite 1750, Boise, ID 83702
email: kcstanger@hollandhart.com, phone: 208-383-3913

This publication is designed to provide general information on pertinent legal topics. The statements made are provided for educational purposes only. They do not constitute legal or financial advice nor do they necessarily reflect the views of Holland & Hart LLP or any of its attorneys other than the author. This publication is not intended to create an attorney-client relationship between you and Holland & Hart LLP. Substantive changes in the law subsequent to the date of this publication might affect the analysis or commentary. Similarly, the analysis may differ depending on the jurisdiction or circumstances. If you have specific questions as to the application of the law to your activities, you should seek the advice of your legal counsel.

Share this entry
  • Share on X
  • Share on LinkedIn
  • Share by Mail
https://hhhealthlawblog.com/wp-content/uploads/2024/05/logo_vertical-v2.png 0 0 admin https://hhhealthlawblog.com/wp-content/uploads/2024/05/logo_vertical-v2.png admin2017-04-28 22:55:412017-04-28 22:55:41CardioNet Settlement Shows Need for Healthcare Providers to Secure Mobile Devices

Idaho Patient Act Timeline


View our Idaho Patient Act Timeline Guide

Holland & Hart

This blog is maintained by the Health Law practice group of Holland & Hart LLP. Visit the Holland & Hart website.

Subscribe to Email Updates

Enter your Email:

Contact

If you have any questions, please contact Kim Stanger.

More COVID-19 Articles


View more COVID-related articles on our Labor & Employment Blog

Categories

Archives

Disclaimer

This publication is designed to provide general information on pertinent legal topics. The statements made are provided for educational purposes only. They do not constitute legal or financial advice nor do they necessarily reflect the views of Holland & Hart LLP or any of its attorneys other than the author. This publication is not intended to create an attorney-client relationship between you and Holland & Hart LLP. Substantive changes in the law subsequent to the date of this publication might affect the analysis or commentary. Similarly, the analysis may differ depending on the jurisdiction or circumstances. If you have specific questions as to the application of the law to your activities, you should seek the advice of your legal counsel.

Privacy Policy

View our privacy policy.

© Copyright 2026 | Holland & Hart LLP - Enfold WordPress Theme by Kriesi
Link to: HIPAA: Should You Ask Patients for Consent to Disclose Information? Link to: HIPAA: Should You Ask Patients for Consent to Disclose Information? HIPAA: Should You Ask Patients for Consent to Disclose Information? Link to: HIPAA: Releases of Information v. Authorization Link to: HIPAA: Releases of Information v. Authorization HIPAA: Releases of Information v. Authorization
Scroll to top Scroll to top Scroll to top