ON THE ROAD · Meet QliqSOFT at Florida Hospice & Palliative Care Association, Orlando, FL →NEW SITE · We rebuilt qliqsoft.com. Current customers: browse it and grade our work → CUSTOMERS: SIGN IN NOW LIVES IN THE TOP BAR →NEW · RPAplus agentic EMR integration: connected even without an API →NOW PUBLIC · How our pricing works: per staff, per patient, published in full →SINCE 2011 · 1,000+ healthcare organizations run on QliqSOFT →ON THE ROAD · Meet QliqSOFT at Florida Hospice & Palliative Care Association, Orlando, FL →NEW SITE · We rebuilt qliqsoft.com. Current customers: browse it and grade our work → CUSTOMERS: SIGN IN NOW LIVES IN THE TOP BAR →NEW · RPAplus agentic EMR integration: connected even without an API →NOW PUBLIC · How our pricing works: per staff, per patient, published in full →SINCE 2011 · 1,000+ healthcare organizations run on QliqSOFT →
Trust CenterSystem Status
Home / Blog / HIPAA Breach Alert: WellPoint fined $1.7M
HIPAA Compliance

HIPAA Breach Alert: WellPoint fined $1.7M

March 12, 2017

In what is believed to be one of the larger HIPAA breach settlements in recent memory, health insurer WellPoint has agreed to settle with HHS for $1.7M stemming from a 2009 and 2010 incident where WellPoint impermissibly disclosed the ePHI of over 600,000 individuals through an unsecured online application. During its investigation, OCR found that WellPoint had not enacted the appropriate administrative, technical, and physical safeguards mandated under HIPAA.

KK
Krishna KurapatiQliqSOFT Blog · March 12, 2017
HIPAA Breach Alert: WellPoint fined $1.7M

In what is believed to be one of the larger HIPAA breach settlements in recent memory, health insurer WellPoint has agreed to settle with HHS for $1.7M stemming from a 2009 and 2010 incident where WellPoint impermissibly disclosed the ePHI of over 600,000 individuals through an unsecured online application. During its investigation, OCR found that WellPoint had not enacted the appropriate administrative, technical, and physical safeguards mandated under HIPAA.

WellPoint discovered the security and privacy lapses when an applicant to the insurer notified the company that she could access PHI of other policyholders through the WellPoint website application. This event further exemplifies to providers that actual acquisition of PHI by unauthorized individuals is not needed to trigger HIPAA violations. Rather, merely the discovery of unsecured data in any form can be enough to trigger an OCR investigation and lawsuit.

wellpoint hipaa breach settlement
KK
Krishna Kurapati · Founder & CEO, QliqSOFT

Founder & CEO of QliqSOFT. Building healthcare communication solutions for 12+ years. Focused on closing gaps in care through technology that enhances human connection.