Business Associate Breach: $2.3M HIPAA Settlement
How inadequate subcontractor management led to cascading security failures and enforcement action
Quick Answer
A business associate providing healthcare IT services settled a $2.3 million OCR penalty for cascading security failures including inadequate subcontractor management, failure to implement required safeguards, and breach notification violations affecting millions of individuals.
Case Overview
A major healthcare IT business associate providing services to multiple covered entities suffered a significant data breach affecting millions of individuals across their client base. The breach exposed protected health information including names, addresses, SSNs, dates of birth, healthcare information, and financial account numbers.
Investigation revealed that the breach resulted from cumulative security failures including:
- Inadequate subcontractor oversight and security requirements
- Failure to implement encryption on critical systems
- Insufficient access controls and user privilege management
- Inadequate audit logging and monitoring
- Delayed breach investigation and notification
- Lack of documented security governance and risk management
In 2017, the business associate agreed to a $2.3 million settlement with OCR and implemented a comprehensive corrective action plan addressing security infrastructure, governance, and breach notification procedures.
What Went Wrong
Inadequate Subcontractor Management
- Business associate engaged subcontractors without adequate security requirements
- Subcontractors were not required to maintain specific security controls
- No audit or oversight mechanism for subcontractor security practices
- Subcontractor agreements did not include required security terms
- Business associate did not conduct due diligence on subcontractor security posture
Insufficient Encryption
- Critical systems and databases lacked encryption of electronic PHI
- Backups were not encrypted
- Data in transit was not consistently encrypted
- No documented encryption standards or implementation requirements
Access Control Deficiencies
- Excessive user privileges across systems
- Weak password policies and authentication mechanisms
- Limited removal of access for terminated employees
- No multi-factor authentication for critical systems
- Insufficient monitoring of privileged account activity
Audit and Monitoring Gaps
- Insufficient logging of system access and changes
- No regular review of access logs or suspicious activity
- Limited real-time monitoring or alerting of security events
- Inadequate database activity monitoring
Breach Investigation Delays
- Extended time to discover the breach due to monitoring gaps
- Delayed investigation to determine scope of compromise
- Delayed notification to affected individuals and covered entities
- Incomplete documentation of investigation findings
Governance and Risk Management
- No documented security policies and procedures
- Risk analysis did not adequately identify vulnerabilities
- No formal incident response procedures
- Limited executive leadership oversight of security
OCR Findings
OCR documented violations across multiple HIPAA rule areas:
Business Associate Rule Violations (45 CFR Part 164)
- § 164.308(b) - Inadequate business associate agreements with subcontractors
- Failure to ensure subcontractors maintained appropriate safeguards
- Inadequate oversight and audit of subcontractor compliance
Administrative Safeguards Violations
- § 164.308(a)(1) - Inadequate security management process and risk analysis
- § 164.308(a)(3) - Insufficient workforce security procedures
- § 164.308(a)(4) - Inadequate information system activity review
- § 164.308(a)(7) - Insufficient security awareness training
Technical Safeguards Violations
- § 164.312(a)(2) - Inadequate access controls
- § 164.312(b) - Insufficient audit controls and logging
- § 164.312(e) - Missing encryption safeguards
Breach Notification Violations
- § 164.404 - Delayed notification to affected individuals
- § 164.406 - Inadequate notice content and delivery
Settlement and Corrective Action
Financial Resolution
- Civil Monetary Penalty: $2.3 million
- Largest BA Settlement: At time of settlement, this was the largest penalty against a business associate
- Payment Terms: Structured settlement with OCR
Required Corrective Actions
- Comprehensive overhaul of security program governance and structure
- Implementation of enterprise-wide encryption for all electronic PHI
- Enhanced access control mechanisms including multi-factor authentication
- Implementation of database activity monitoring and real-time alerting
- Comprehensive audit logging and regular log review procedures
- Enhanced subcontractor security requirements and ongoing audit procedures
- Updated business associate agreements with all subcontractors
- Workforce security training program covering HIPAA and vendor management
- Formal incident response procedures and breach notification procedures
- Regular security assessments and penetration testing
- Annual third-party audits of security compliance
Ongoing Monitoring
OCR retained authority to conduct follow-up audits and compliance reviews to ensure sustained implementation of corrective actions over multiple years.
Lessons Learned
Business Associates Have Direct HIPAA Obligations
Business associates are not merely extensions of covered entities—they have direct obligations under HIPAA to maintain safeguards protecting electronic PHI. OCR enforces these obligations directly against business associates, not just through covered entities. Business associates cannot rely on covered entities to police their compliance.
Subcontractor Management Is a Critical Control
Business associates that use subcontractors must establish clear security requirements, include those requirements in agreements, and conduct ongoing audit and oversight of subcontractor compliance. Failures in subcontractor security cascade to the business associate's breach risk and liability.
Scale Does Not Excuse Security
This business associate served multiple covered entities and held PHI for millions of individuals. The scale of operations increased both the importance of security and the consequence of failures. OCR determined that the penalty amount should reflect the number of individuals affected and severity of security failures.
Encryption and Monitoring Are Fundamental
The combination of unencrypted data and inadequate monitoring allowed this breach to go undetected for an extended period and affected millions of individuals. Encryption and monitoring (especially for database access) are fundamental controls that should not be optional.
Breach Investigation and Notification Cannot Be Delayed
Delays in investigation and notification violated both the Security Rule (duty to protect) and Breach Notification Rule. Swift response to suspected breaches is essential to minimize impact and comply with notification requirements.
Governance Matters as Much as Technology
This case involved both technical control failures (encryption, monitoring) and governance failures (risk assessment, incident response procedures, subcontractor management). Strong security requires both technical implementation and organizational governance.
Prevention Checklist for Business Associates
Subcontractor and Vendor Management
Technical Safeguards
Access Controls
Monitoring and Audit
Risk Management and Governance
Incident Response and Notification
Frequently Asked Questions
Yes. Business associates have direct HIPAA obligations and can be enforced against directly by OCR. They are not protected by being a contractor—they must maintain safeguards protecting electronic PHI and can face penalties and enforcement actions for violations. Covered entities may also pursue contractual remedies against business associates for violations, but this does not limit OCR's direct enforcement authority.
A business associate is a contractor that creates, receives, maintains, or transmits PHI on behalf of a covered entity. A subcontractor is a vendor of a business associate that also handles PHI. Business associates have direct HIPAA obligations. Business associates must ensure subcontractors also meet HIPAA requirements through business associate agreements and oversight. Both ultimately must comply with HIPAA, though the contractual relationships differ.
A covered entity can be liable to OCR for inadequate oversight and management of business associates, but the business associate also has direct liability for their own violations. OCR may enforce against both the covered entity (for inadequate BA management) and the business associate (for security violations). Covered entities can also pursue contractual remedies against business associates, but this does not eliminate OCR's enforcement authority against the covered entity for inadequate BA oversight.
A business associate agreement must specify that the BA will maintain appropriate safeguards for PHI, limit use and disclosure to permitted purposes, implement required administrative, physical, and technical safeguards, provide breach notification to the covered entity, permit audits and inspections, return or destroy PHI upon termination, and ensure subcontractors meet equivalent requirements. The agreement should be specific about security requirements and oversight mechanisms rather than generic.
Strengthen Your Business Associate Management
Assess whether your organization maintains adequate oversight and security requirements for business associates and subcontractors, or face potential enforcement action and liability.
Evaluate Your BA Program