Skip to main content
Best Practices

OCR, Affinity Health Plan Reach Settlement on Photocopier Breach Case

In a week including several high profile HIPAA breach incidents and settlements, the Department of Health and Human Services announced the biggest one of all: a settlement agreement with Affinity Health Plan stemming from an incident in 2010 when it was discovered that an improperly wiped photocopier compromised the PHI of over 300,000 patients. Affinity and HHS agreed to settle the case for $1,215,780.

2 min read
photocopier data breach case|HIPAA data breaches in the healthcare field

In a week including several high profile HIPAA breach incidents and settlements, the Department of Health and Human Services announced the biggest one of all: a settlement agreement with Affinity Health Plan stemming from an incident in 2010 when it was discovered that an improperly wiped photocopier compromised the PHI of over 300,000 patients. Affinity and HHS agreed to settle the case for $1,215,780.

The Data Breach Incident in the Healthcare Field

What was notable about this particular incident was not necessarily the high settlement figure or even the large number of patients involved, but the bizarre nature of the incident itself. In the period leading up to the incident, the New York-based health plan had been leasing the digital photocopier. After the next user, CBS, purchased the copier from the leasing agent, it discovered hundreds of thousands of patient records that had not been deleted off the hard drive before the end of Affinity’s lease term.

HIPAA data breaches in the healthcare field

This incident underscores the greater risk that compliance or information officers need to take into account in their risk assessments: the human factor. State-sponsored cyber terrorism might get all of the press headlines, but a healthcare provider is far more susceptible to something as simple as a lost laptop or an improperly wiped digital device. As mentioned in our webinar this past Wednesday, the proliferation of IT and other healthcare digital products is empowering healthcare organizations to deliver better care to their patients. Nevertheless, the loss of patient data through these devices should always be at the forefront of a CIO’s mind.

The Cost of a Healthcare Data Breach

As with all data breach settlements with HHS, the settlement figure only shows us the tip of the financial iceberg. After taking into account the costs associated with patient notification and credit monitoring services that a covered entity must legally include, the actual cost of this incident is very likely to represent a multiple of the HHS settlement amount.

Frequently Asked Questions

Find answers to common questions about this topic.

Beyond HHS settlement amounts, healthcare organizations must cover patient notification costs, credit monitoring services, and other legal requirements. These additional expenses often represent a multiple of the original settlement figure, making the true financial impact significantly higher.

Healthcare organizations should implement proper data sanitization procedures before returning leased digital equipment, including photocopiers, computers, and other devices with hard drives. Establish clear protocols for wiping all PHI from device storage and verify complete data removal before lease termination.

Digital photocopiers, multifunction printers, laptops, tablets, and various healthcare IT equipment often contain hard drives that store PHI. These devices can retain patient information even after normal use, requiring proper data sanitization protocols.

While cyberattacks receive media attention, healthcare organizations face higher risks from human factors like lost devices, improperly wiped equipment, or procedural failures. These incidents are more common and often easier to prevent with proper training and protocols.

CIOs should balance the benefits of new digital healthcare products with robust data security measures. Prioritize comprehensive risk assessments that account for device lifecycle management, including secure data disposal and employee training on PHI protection protocols.

Krishna Kurapati

Written by

Krishna Kurapati

Founder & CEO

Founder & CEO of QliqSOFT with 20+ years of healthcare technology experience.

View all posts

Related Articles

wellpoint hipaa breach alert|wellpoint hipaa breach settlement
Best Practices

HIPAA Breach Alert: WellPoint fined $1.7M

In what is believed to be one of the larger HIPAA breach settlements in recent memory, health insurer WellPoint has agreed to settle with HHS for $1.7M stemming from a 2009 and 2010 incident where WellPoint impermissibly disclosed the ePHI of over 600,000 individuals through an unsecured online application. During its investigation, OCR found that WellPoint had not enacted the appropriate administrative, technical, and physical safeguards mandated under HIPAA.

Krishna KurapatiKrishna Kurapati
1 min read
ohsu data breach lacking healthcare it|medical data breach and security
Best Practices

OHSU Data Breach: Where Health IT is lacking

In an interesting piece posted over the weekend at The Health Care Blog, Dr. David Do described a recent reported data breach by the Oregon Health & Science University. The event, which was reported to patients at the end of July, was triggered when OHSU administrators discovered that medical residents were storing patient records in Google Drive, a free, cloud-based document storage platform.

Krishna KurapatiKrishna Kurapati
3 min read
2m left