CVS to pay $2.25 million to settle HIPAA violation

By Dan Kaplan

June 18, 2010 Updated Feb 19, 2009 at 12:32 PM EST

CVS Caremark must pay $2.25 million to settle federal charges that its employees threw out personal information about patients into garbage bins.

The Federal Trade Commission (FTC) said on Wednesday that the company -- which operates about 6,300 retail outlets -- lacked proper procedures for discarding sensitive data about customers when, in 2006, pharmacy workers unloaded pill bottles, medication instruction sheets and computerized order information into open trash containers.

This personal information was protected under the Health Insurance Portability and Accountability Act (HIPAA), according to the FTC.

In addition to the settlement fee, CVS Caremark now will be required to establish policies for disposing of personal information and will have to succumb to a biennial audit by a third party.

Experts told SCMagazineUS.com on Wednesday that the settlement could signal a shift by regulators, which traditionally have been lax in going after alleged HIPAA offenders.

"Until these regulations have teeth, they're meaningless," said Kurt Baumgarten, vice president of information security at Peritus Security, which advises companies on compliance. "If they're actually going to start using regulations for the purpose they were designed, the only way to unfortunately crack down on [violating] best practices is to punish the organizations that are basically playing a game of rolling the dice."

CVS denied any wrongdoing but decided to settle to avoid costly litigation, according to a company statement.




What are your thoughts CLICK HERE to leave us a "QUESTION OF THE DAY” comment.

Want to be in the know for the next weather event, the next school closing or the next big breaking news story?

TextCaster alerts from 21Alive.com are your defining source for instant information delivered right to your cell phone and email. It's free, easy and instant. Sign-Up Now!

Powered by Summit City Chevrolet



© Copyright 2014, A Granite Broadcasting Station. All rights reserved. This material may not be published, broadcast, rewritten or redistributed.

To submit a comment on this article, your email address is required. We respect your privacy and your email will not be visible to others nor will it be added to any email lists.