ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Montefiore Medical Center settles HIPAA violation allegations with $4.75 million penalty

The Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has imposed its first financial penalty of the year, with Montefiore Medical Center agreeing to settle alleged violations of the Health Insurance Portability and Accountability Act (HIPAA) by paying a $4.75 million penalty.

 

OCR’s penalty against Montefiore Medical Center marks the largest financial penalty imposed since January 2021’s $5.1 million penalty for Excellus Health Plan, and it already surpasses OCR’s total collections from HIPAA enforcement actions in 2023.

 

The investigation into Montefiore Medical Center revealed multiple failures to comply with the HIPAA Security Rule, stemming from a report of a breach of the protected health information (PHI) of 12,517 patients. Despite the breach affecting fewer individuals compared to the Excellus investigation, the nature of Montefiore Medical Center’s HIPAA violations was deemed severe by OCR.

 

The violations originated from an incident in May 2015, when the New York Police Department uncovered evidence of criminal HIPAA violations at the medical center. A former employee had unlawfully accessed and sold the PHI of thousands of patients to identity thieves over six months in 2013.

 

OCR’s investigation found that Montefiore Medical Center failed to conduct a thorough risk analysis, implement procedures to review activity in information systems and establish mechanisms to record and examine such activity. Subsequent incidents involving employees’ unauthorized access to patient records further underscored the medical center’s shortcomings in safeguarding patient information.

 

Despite settling the allegations without admission of wrongdoing, Montefiore Medical Center agreed to implement a corrective action plan, including conducting thorough risk assessments, developing risk management plans, and enhancing hardware and software mechanisms for monitoring activity in information systems.

 

OCR Director Melanie Fontes Rainer emphasized the importance of addressing cyber threats swiftly and diligently in today’s healthcare landscape, highlighting the severity of cyber-attacks targeting patient records, even from within organizations.

 

Montefiore Medical Center confirmed strengthening security measures following the breach, including terminating the involved employee, enhancing monitoring capabilities, and increasing training and outreach efforts to reinforce HIPAA compliance and patient privacy responsibilities.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543