HHS Settles BCAA HIPAA Cybersecurity Violations Investigation for $90K

November 13, 2024

INCIDENT

The breach at BCAA (Brian County Ambulance Authority), reported to OCR in May 2022, resulted in the encryption of files containing the ePHI of 14,273 patients. OCR’s investigation revealed that BCAA had not conducted a compliant risk analysis to identify potential risks and vulnerabilities to ePHI in its systems, a fundamental requirement under the HIPAA Security Rule.

Under the terms of the resolution agreement, BCAA has agreed to pay $90,000 and adopt a corrective action plan, which will be monitored by OCR over the next three years

Incident Date

November 12, 2022

Estimated Cost

$90,000 non-compliance fine

Type of Malware

No Malware identified

Threat Source

No threat source identified