On December 5, 2024, the U.S. Department of Health and Human Services (“HHS”) Office for Civil Rights (“OCR”) announced a penalty of $548,265 against Children’s Hospital Colorado (“CHC”) in connection with a series of alleged data breaches that occurred in 2017 and 2020. In September 2017, CHC reported to OCR a phishing attack that compromised an employee’s email account. OCR’s investigation revealed that the breach occurred because multi-factor authentication was disabled on the employee’s email account. According to OCR, the second breach in April 2020 occurred in part because two workforce members provided unknown third parties with access to their email accounts by accepting a multi-factor authentication access request that neither individual had initiated. OCR also determined that CHC violated the HIPAA Privacy Rule’s requirement to train workforce members on the HIPAA Privacy Rule and the HIPAA Security Rule’s requirements regarding conducting risk analyses to determine the risks and vulnerabilities to ePHI in an organization’s systems.
In June 2024, OCR issued a Notice of Proposed Determination seeking to impose a civil monetary penalty. CHC did not contest OCR’s findings. Accordingly, OCR issued the Notice of Final Determination in September 2024.