HHS’ Office for Civil Rights Settles Malicious Insider Cybersecurity Investigation with Montefiore Medical Center for $4.75 Million
The U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR), has reached a $4.75 million settlement with Montefiore Medical Center, a non-profit hospital system based in New York City, following an investigation into potential violations of the Health Insurance Portability and Accountability Act (HIPAA) Security Rule. The settlement addresses several data security failures by Montefiore that allowed an employee to steal and sell patients’ protected health information over a six-month period.