Advocate Health Care Network, then the largest fully integrated healthcare system in Illinois, reported three separate 2013 breaches to the HHS Office for Civil Rights that collectively exposed the electronic protected health information of approximately 4,029,530 patients. The largest incident involved the July 15, 2013 overnight theft of four unencrypted desktop computers from an Advocate Medical Group administrative office in Park Ridge, Illinois, which contained demographic information, clinical data, health insurance information, names, addresses, dates of birth, credit card numbers with expiration dates, and Social Security numbers for roughly four million patients. A second report concerned the unauthorized network access of a billing services business associate, and a third covered the theft of an additional unencrypted laptop from an Advocate workforce member's vehicle. OCR's investigation identified failures to conduct an accurate, enterprise-wide risk analysis, implement physical safeguards for workstations, obtain HIPAA-compliant business associate assurances, and reasonably safeguard an unencrypted laptop left in an unattended vehicle. On August 4, 2016 Advocate agreed to pay $5.55 million and adopt a robust corrective action plan, at the time the largest HIPAA settlement against a single entity, a record that stood until Anthem's $16 million resolution in October 2018.
Blog
Insights on AI security and development
Learn how to protect your code, understand AI risks, and build secure workflows with expert insights.

