Medical Clinic Faces $240,000 Fine in Ransomware Investigation

Oct. 3, 2024, 7:12 PM UTC

A Southern California medical clinic is facing a $240,000 civil monetary penalty for violations of the Health Insurance Portability and Accountability Act of 1996, following a ransomware attack breach report investigation, the Health and Human Services Department announced Thursday.

According to the HHS, Providence Medical Institute reported in 2018 that its systems were impacted by a series of ransomware attacks that affected the electronic protected health information of 85,000 individuals. An HHS investigation determined that servers containing protected health information were encrypted with ransomware three times.

The HHS said it found two potential violations of the HIPAA Security Rule, including ...

Learn more about Bloomberg Law or Log In to keep reading:

Learn About Bloomberg Law

AI-powered legal analytics, workflow tools and premium legal & business news.

Already a subscriber?

Log in to keep reading or access research tools.