Highlights
HIPAA business associates that have government contracts can face FCA penalties in addition to sanctions under HIPAA
A web-hosting company paid $293,771 to settle FCA allegations that it failed to secure personal information
This settlement is confirmation that the DOJ will continue using the FCA to address HIPAA violations and substandard cybersecurity practices
On March 14, 2023, the U.S. Department of Justice (DOJ) announced the settlement of a case involving alleged violations of the False Claims Act (FCA) as a result of cybersecurity failures and breach of HIPAA-protected health information. Obtained under the Civil Cyber-Fraud Initiative, this settlement emphasizes that HIPAA business associates that have government contracts can face FCA penalties from federal law enforcement in addition to the monetary penalties pursued by the Office for Civil Rights, which enforces HIPAA.
Under the settlement agreement, Jelly Bean Communications Design LLC agreed to pay $293,771 to resolve FCA allegations that it failed to secure personal information on the Florida Healthy Kids Corporation (FHKC) website, which Jelly Bean created, hosted and maintained. FHKC contracts with the state of Florida to provide services for the State Children’s Health Insurance Program. The federal government funded 86 percent of the payments made from FHKC to Jelly Bean.
According to the settlement agreement, in early December 2020 it became apparent that more than 500,000 applications...
Read Full Story:
https://news.google.com/rss/articles/CBMid2h0dHBzOi8vYnRsYXcuY29tL2luc2lnaHRz...