Civil Money Penalty, Jackson Health System
OCR Imposes a $2.15 Million Civil Money Penalty against Jackson Health System for HIPAA Violations
Cite as HHS OCR Civil Money Penalty, Jackson Health System (2019-10-23)
DEPARTMENT OF HEALTH & HUMAN SERVICES
Office of the Secretary
Voice - (404) 562-7886, (800) 368-1019
Office for Civil Rights, Southeast Region
TDD - (404) 562-7884, (800) 537-7697
Atlanta Federal Center, Suite 16T70
Fax - (404) 562-7881
61 Forsyth Street, S.W.
http://www.hhs.gov/ocr
Atlanta, GA 30303
Sent via U.S. Certified Mail and Electronic Mail
July 22, 2019
JUL 2 2 2019
Judy Ringholz, RN, JD, CHC
VP & Chief Compliance Officer
Office ofCompliance and Ethics
Jackson Health System
Jackson Medical Towers
1500 NW 12th A venue
1st Floor, Suite 102
Miami, FL 33136
Email: judy.ringholz@jhsmiami.org
Re:
Jackson Health System
OCR Transaction Numbers: 13-165455, 15-217816, & 16-231802
NOTICE OF PROPOSED DETERMINATION
Dear Ms. Ringholz:
Pursuant to the authority delegated by the Secretary ofthe United States Department ofHealth and
Human Services (HHS) to the Office for Civil Rights (OCR), I am writing to inform you that OCR
is proposing to impose a civil money penalty (CMP) of$2,154,000 against Jackson Health System
(JHS) which is governed by the Public Health Trust (PHT) (created by county ordinance) acting
on behalfofthe Miami-Dade Board ofCounty Commissioners.
This proposed action is being taken under the Health Insurance Portability and Accountability Act
of1996 (HIP AA),§ 262(a), Pub.L. 104-191, 110 Stat. 1936, as amended by the Health Information
Technology for Economic and Clinical Health (HITECH) Act, Public Law 111-5, Section 13410,
codified at 42 U.S.C. § 1320d-5, and under 45 C.F.R. Part 160, Subpart D.
I.
The Statutory Basis for the Proposed CMP
The Secretary of HHS is authorized to impose CMPs (subject to the limitations set forth at 42
Page l of 12
U.S.C. § 1320d-5(b)) against any covered entity, as described at 42 U.S.C. § 1320d-l(a), that
violates a provision of Part C (Administrative Simplification) of Title XI of the Social Security
Act. See HIP AA,§ 262(a), as amended, 42 U.S.C. § 1320d-5(a). This authority includes violations
ofthe applicable provisions ofthe Federal Standards for Privacy ofIndividually Identifiable Health
Information and/or the Security Standards for the Protection of Electronic Protected Health
Information (45 C.F.R. Parts 160 and 164, Subparts A, C, and E, the Privacy and Security Rules)
and the Breach Notification Rule (45 C.F.R. Parts 160 and 164, Subpart D), pursuant to Section
264(c) of HIP AA. The Secretary has delegated enforcement responsibility for the HIP AA Rules
to the Director of OCR. See 65 Fed. Reg. 82,381 (Dec. 28, 2000) and 74 Fed. Reg. 38630 (July
27, 2009). OCR is authorized under the HITECH Act § 13410, 42 U.S.C. § 1320d-5(a)(3), to
impose CMPs for violations occurring on or after February 18, 2009, of:
• A minimum of$100 for each violation where the covered entity or business associate did
not know and, by exercising reasonable diligence, would not have known that the
covered entity or business associate violated such provision, except that the total amount
imposed on the covered entity or business associate for all violations ofan identical
requirement or prohibition during a calendar year may not exceed $25,000.
• A minimum of$1 ,000 for each violation due to reasonable cause and not to willful neglect,
except that the total amount imposed on the covered entity or business associate for all
violations ofan identical requirement or prohibition during a calendar year may not exceed
$100,000. Reasonable cause means an act or omission in which a covered entity or
business associate knew, or by exercising reasonable diligence would have known, that the
act or omission violated an administrative simplification provision, but in which the
covered entity or business associate did not act with willful neglect.
• A minimum of $10,000 for each violation due to willful neglect and corrected within 30
days, except that the total amount imposed on the covered entity or business associate for
all violations of an identical requirement or prohibition during a calendar year may not
exceed $250,000.
• A minimum of$50,000 for each violation due to willful neglect and uncorrected within 30
days, except that the total amount imposed on the covered entity or business associate for
all violations of an identical requirement or prohibition during a calendar year may not
exceed $1 ,500,000.
• As required by law, OCR has adjusted the CMP ranges for each penalty tier for inflation.
The adjusted amounts are applicable only to CMPs whose violations occurred after
November 2, 2015.
OCR is precluded from imposing a CMP unless the action is commenced within six years from
the date ofthe violation.
II.
Findings of Fact
1. JHS is a "covered entity'' within the definition set forth at 45 C.F .R. § 160.103, and,
Page 2 of 12
as such, is required to comply with the requirements of the HIPAA Privacy, Security
and Breach Notification Rules.
2. JHS is a nonprofit academic medical system based in Miami, Florida that operates a
number of hospitals and medical centers throughout Florida and provides health care
to an average of650,000 patients annually.
3. JHS creates, maintains, receives, and transmits protected health information (PHI)
related to patients who receive health care services from JHS facilities.
4. On August 22, 2013, JHS submitted a Breach Notification Report ("Report") to OCR.
The Report indicated a loss ofpaper records for 1,4 71 patients from the Jackson
Memorial Hospital's Health Information Management (HIM) department in January
2013 ("January 2013 loss").
5. In July 2015, OCR became aware ofmultiple media reports disclosing the PHI of a
JHS hospital patient, a well-known NFL player. An ESPN reporter also shared a
photograph ofan electronic display board in a JHS operating room and a paper
schedule containing the PHI ofthe same patient.
6. On October 26, 2015, OCR notified JHS that it opened a compliance review relating
to the media disclosures ofthe NFL player's PHI.
7. On February 25, 2016, JHS timely submitted a Report stating that a photograph was
taken ofan operating room electronic display board which displayed the PHI oftwo
individuals including "a well-known person in the community."
8. On February 19, 2016, JHS submitted a Report to OCR reporting that a JHS
employee had been selling patient information since July 2011. JHS also reported
that 24, 188 patients' records had been inappropriately accessed by the employee since
2011.
9. The Security Rule Security Management Process standard, 45 C.F.R. § 164.308(a)(l),
requires that a covered entity must, in accordance with § 164.306, implement policies
and procedures to prevent, detect, contain, and correct security violations.
l 0. In order to implement the Security Management Process standard, a covered entity
must comply with the specific requirements or instructions for implementing the
standards as set forth in the relevant implementation specifications.
11. Specifically, the implementation specification regarding risk analysis, at 45 C.F .R.
§164.308(a)(l)(ii){A), requires a covered entity to conduct an accurate and thorough
assessment ofthe potential risks and vulnerabilities to the confidentiality, integrity,
and availability ofthe electronic PHI (ePHI) held by the covered entity.
12. In response to several data requests issued by OCR, JHS provided "risk analyses"
Page 3 of12
conducted on its behalf by third parties in 2014, 2015, 2016 and 2017. JHS also
provided internal assessments conducted by JHS in 2009, 2012, and 2013.
13. The risk analyses conducted before 2017 erroneously identified several provisions of
the Security Rule as "not applicable" to JHS.
14. The risk analysis completed on September 30, 2014, failed to include all ePHI
created, received, maintained or transmitted by JHS (i.e. deficient in scope) and did
not identify the totality of threats and vulnerabilities that exist in its systems.
15. Further, the implementation specification regarding risk management, at 45 C.F.R. §
164.308(a)(l)(ii)(B), requires a covered entity to implement security measures
sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level to
comply with§ 164.306(a).
16. JHS did not remediate risks, threats and vulnerabilities identified specifically by the
2014 risk analysis to a reasonable and appropriate level. For example, while
recommendations were provided by the third party who conducted the risk analysis,
JHS did not provide evidence or documentation ofa response to those
recommendations.
17. A subsequent risk analysis was completed by a third party on September 30, 2015.
It did not include all ePHI created, received, maintained or transmitted by JHS (i.e.
deficient in scope) and did not identify the totality ofthreats and vulnerabilities that
exist in its systems. Moreover, some sections ofthe risk analysis were left blank.
18. JHS also did not remediate risks, threats and vulnerabilities identified specifically by
the 2015 risk analysis to a reasonable and appropriate level. For example, while
recommendations were provided by the third party, JHS did provide evidence or
documentation ofa response to those recommendations. The same "high risk"
threats identified in the 2014 risk analysis were still identified as ''high risk" on the
2015 analysis. JHS failed to implement security measures to reduce these risks and
vulnerabilities.
19. A subsequent risk analysis was completed by a third party on September 8, 2016. It
was not enterprise-wide to include all ePHI created, received, maintained or
transmitted by JHS (i.e. deficient in scope) and did not identify the totality ofthreats
and vulnerabilities that exist in its systems. Some sections ofthe risk analysis were
left blank.
20. JHS did not remediate risks, threats and vulnerabilities identified specifically by the
2016 risk analysis to a reasonable and appropriate level. For example, while
recommendations were provided by the third party, JHS did not provide evidence or
documentation ofa response to those recommendations. The same "high risk"
threats identified above in the 2014 and 2015 risk analyses were still identified as
"high risk" on this analysis. JHS did not provide any evidence that it had made
Page 4 of12
efforts to implement security measures to reduce these risks and vulnerabilities.
21. The risk analysis conducted in 2017 was compartmentalized by department and not
thorough in scope. For example, only the main campus ofJHS was included in the
analysis. In addition, the methodology ofthe 2017 analysis was largely limited to
policy review and interviews with staff.
22. The implementation specification regarding information systems activity review, at
45 C.F.R. § 164.308(l)(ii)(D), requires a covered entity to implement procedures to
regularly review records ofinformation system activity, such as audit logs, access
reports, and security incident tracking reports.
23. While JHS had the capability to create audit logs and access reports for systems that
contain ePHI, it did not regularly review these logs.
24. Specifically, despite procedures JHS alleges were in place, JHS failed to determine
that an employee was impermissibly accessing the ePHI of24, 188 patients for over
five years. An anonymous caller notified JHS's Office ofCompliance and Ethics on
January 4, 2016 that the employee was selling patients' ePHI.
25. From July 22, 2013 through January 27, 2016, JHS failed to implement policies and
procedures to prevent, detect, contain, and correct security violations as required by
45 C.F.R. § 164.308(a)(l). Specifically, JHS failed to conduct an accurate and
thorough risk analysis, implement security measures sufficient to reduce risks and
vulnerabilities to a reasonable and appropriate level, and implement procedures to
regularly review records ofinformation system activity.
26. The HIPAA Security Rule Information Access Management standard at 45 C.F.R.
§ 164.308(a)(4) requires a covered entity to implement policies and procedures for
authorizing access to ePHI that are consistent with the applicable requirements ofthe
HIPAA Privacy Rule at 45 CFR Subpart E.
27. Among other things, the HIP AA Privacy Rule requires a covered entity to identify
persons or classes ofpersons in its workforce who need access to PHI to carry out
their duties, identify the category or categories of PHI to which access is needed, and
make reasonable efforts to limit access to the persons and categories identified. See
45 C.F.R. § 164.514(d).
28. JHS admits that for over five years an employee had access to ePHI that she "did not
have the proper authorization or authority to access" despite having written policies
and procedures in place, demonstrating a failure to implement such policies on an
operational basis.
29. During the course ofits investigation, OCR learned that a nurse who treated the NFL
player in the operating room and who had legitimate access to his PHI at that time
impermissibly continued to access his medical record after she no longer had a job
Page S of12
related reason to do so.
30. Additionally, a second employee was found to be accessing the NFL player's records.
This demonstrates users' ability to access ePHI without authorization. While all of
these employees were sanctioned, their broad and excessive access evidences a lack
ofrestriction, review and/or modification ofthe appropriate levels of access to ePHI.
31. From July 22, 2013 through January 29, 2016, JHS failed to implement policies and
procedures for granting access to ePHI consistent with the applicable requirements of
the Privacy Rule, including restricting access to ePHI to the minimum necessary as
required by 45 C.F.R. §164.308(a)(4) and restricting access to the classes of
employees who need the ePHI in order to fulfill their job duties as required by 45
C.F.R. § 164.514(d).
32. The HIP AA Breach Notification Rule requires a covered entity to notify the Secretary
following the discovery of a breach ofunsecured protected health information. 45
C.F.R. § 164.408.
33. Specifically, for breaches ofunsecured protected health information involving 500 or
more individuals, a covered entity shall provide the notification required without
unreasonable delay and in no case later than 60 calendar days after discovery ofa
breach. 45 C.F.R. § 164.408(b).
34. A breach is treated as discovered by a covered entity as of"the first day on which
such breach is known to the covered entity, or, by exercising reasonable diligence
would have been known to the covered entity" and a covered entity "is deemed to
have knowledge ofa breach ifsuch breach is known ...to any person, other than the
person committing the breach, who is a workforce member or agent ofthe covered
entity...." 45 C.F.R § 164.404(a)(2).
35. A JHS employee discovered a loss ofpaper records in the Health Information
Management Department in December 2012 and reported the matter to a JHS
supervisor on or before December 31, 2012. These records contained the PHI of715
patients in three boxes.
36. On January 14, 2013, a JHS employee reported to a JHS supervisor that two boxes of
emergency room patient records went missing from the Health Information
Management Department. These records contained the PHI of756 patients.
37. The supervisor did not report the December 2012 loss to JHS Security Services until
March 2013, during the JHS internal investigation ofthe January 2013 incident.
38. In accordance with 45 C.F.R. § 164.408(b ), this Report was due to HHS on or before
March 15, 2013.
39. JHS did not submit this Report to HHS until August 22, 2013. Thus, JHS was at least
Page 6of12
days late reporting 160 days late reporting the breach.
40. Moreover, even though the identified number ofindividuals affected in this Report
included those affected by both the December 2012 loss and the January 2013 loss,
the Report only referred to the January 2013 loss.
41. JHS did not submit an addendum to the Report reflecting the December 2012 loss
until June 7, 2016.
42. JHS admits that before implementing its HIP AA Privacy Manual & Policies in
October 2013 (after the breach involving the loss ofpaper records), "there were no
previous policies as it related to breaches," including breach response, breach risk
assessment, and breach notification procedures.
43. Further, while JHS implemented a breach notification policy in October 2013, the
policy does not include specific procedures for effectively providing notification
under the Breach Notification Rule.
44. JHS failed to provide timely and accurate notification to the Secretary ofHHS ofthe
breach caused by the loss of paper records involving more than 500 individuals. (See
45 C.F.R. § 164.408).
45. On June 17, 2019, OCR issued a Letter of Opportunity and informed JHS that OCR's
investigation indicated that JHS failed to comply with the Security and Breach
Notification Rules and that this matter had not been resolved by informal means despite
OCR's attempts to do so. The letter stated that pursuant to 45 C.F.R. § 160.312(a)(3),
OCR was informing JHS of the preliminary indications of non-compliance and
providing JHS with an opportunity to submit written evidence of mitigating factors
under 45 C.F.R. § 160.408 or affirmative defenses under 45 C.F.R. § 160.410 for
OCR's consideration in making a determination of a CMP pursuant to 45 C.F.R.
§ 160.404. The letter stated that JHS could also submit written evidence to support a
waiver ofa CMP for the indicated areas ofnon-compliance. Each act ofnoncompliance
was described in the letter.
46. The Letter of Opportunity was delivered to JHS and received by JHS's agent on June
17, 2019.
47. JHS submitted its response to OCR's Letter of Opportunity on July 17, 2019. JHS
response stated, "[a]s revealed through our correspondence over the past several years,
[JHS] has significantly enhanced its Privacy and Security programs in a number of
different ways, and it is committed to continue to improve upon those programs."
48. JHS's response did not provide any written evidence of mitigating factors under 45
C.F.R. § 160.408 or affirmative defenses under 45 C.F.R. § 160.410 for OCR's
consideration in making a determination ofa CMP pursuant to 45 C.F .R. § 160.404.
Page 7 of 12
49. JHS also did not submit any written evidence to support a waiver of a CMP for the
indicated areas of non-compliance.
50. OCR obtained the authorization of the Attorney General of the United States prior to
issuing this Notice ofProposed Determination to impose a CMP.
III.
Basis for CMP
Based on the above findings of fact, we have determined that JHS is liable for the following
violations ofthe HIPAA Rules and, therefore, is subject to a CMP.
1. JHS failed to implement policies and procedures to prevent, detect, contain, and
correct security violations, because it (a) failed to conduct an accurate and thorough
assessment ofthe potential risks and vulnerabilities to the confidentiality, integrity,
and availability ofePHI held by JHS, (b) failed to implement security measures
sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level, on
a continuing basis through the present, and (c) failed to review system activity in
violation of45 C.F.R. §§ 164.308(a)(l)(i), 164.308(a)(l)(ii)(A), and
164.308(a)(l)(ii)(B) and 164.308(a)(l)(ii)(D). OCR has determined the violation
extends the maximum statutory allowed time, which is 6 years, using the earliest date
ofthe violation as July 22, 2013. OCR has determined that the appropriate penalty
tier for this violation is reasonable cause.
a. Calendar Year 2013: 163 days from July 22, 2013 to December 31, 2013
b. Calendar Year 2014: 365 days from January 1, 2014 to December 31 , 2014
c. Calendar Year 2015: 365 days from January 1, 2015 to December 31, 2015
d. Calendar Year 2016: 26 days from January 1, 2016 to January 27, 2016
2. JHS failed to comply with the Information Access Management standard and
implementation specification ofthe HIPAA Security Rule at 45 C.F.R.
§ 164.308(a)(4) when it failed to restrict workforce member access to ePHI to the
minimum necessary to accomplish their job duties. OCR has determined that the
appropriate penalty tier for this violation is reasonable cause.
a. Calendar Year 2013 : 163 days from July 22, 2013 to December 31 , 2013
b. Calendar Year 2014: 365 days from January 1, 2014 to December 31, 2014
c. Calendar Year 2015: 365 days from January 1, 2015 to December 31 , 2015
d. Calendar Year 2016: 28 days from January 1, 2016 to January 29, 2016
3. JHS was in violation ofthe Notification to the Secretary standard and implementation
specification ofthe HIP AA Breach Notification Rule at 45 C.F.R. § 164.408 when it
failed to provide timely and accurate notification to the Secretary of HHS ofthe
breach caused by a loss ofpaper records. OCR has determined that the appropriate
penalty tier for this violation is willful neglect, not corrected.
a. Calendar Year 2013: 31 days from July 22, 2013 to August 22, 2013.
Page 8 of12
IV.
No Affirmative Defenses
By its June 17, 2019 Letter of Opportunity, OCR offered JHS the opportunity to provide written
evidence ofaffirmative defenses within thirty (30) days from the date ofreceipt of that letter. As
noted in Paragraph 11.47 above, JHS submitted its response to OCR by letter dated July 17, 2019,
and did not provide any written evidence ofaffirmative defenses for consideration under §
160.410. Instead, JHS 's response merely referenced the "correspondence" previously provided
to OCR "over the past several years." Accordingly, OCR notes that during the course of its
investigation, it considered all ofthe evidence provided by JHS and has determined there are no
applicable affirmative defenses.
V.
Factors Considered in Determining the Amount of the CMP
In determining the amount of the CMP, OCR has considered the following factors in accordance
with 45 C.F.R. § 160.408.
First, OCR considered the nature and extent ofthe violations. The violations ofthe Security
Rule, identified above, evidence wide-spread and longstanding deficiencies in protecting PHI to
prevent impermissible disclosures. For many years prior to OCR's initiation ofthe above
referenced compliance review, JHS continually failed to conduct a sufficient, enterprise-wide
risk analysis that meets the requirements of45 C.F.R. § 164.308(a)(l)(ii)(A). Further, over the
course ofmany years, no evidence was provided by JHS to support measures implemented to
remediate risks, threats and vulnerabilities identified specifically by risk analyses to a reasonable
and appropriate level. Additionally, due to JHS's longstanding failure to adequately review
information system activity, and failure to limit access to ePHI to the minimum necessary based
on job duty, an employee was able to abuse her access to ePHI undetected in JHS systems from
2011to2016 and accessed the PHI of24,189 patients without a job related reason. The
employee admitted to selling the PHI of2,000 ofthose patients for purposes ofidentity theft.
Lastly, despite JHS's investigation oflost paper records ongoing since January 2013, JHS did not
inform HHS ofthe breach until August 22, 2013 and did not file an addendum to that Report to
accurately describe the breach until June 7, 2016. In determining the amount ofthe CMP, OCR
considered the amount of time that JHS remained out of compliance with 45 C.F.R. §
164.308(a)(l), 45 C.F.R. §164.308(a)(4), and 45 C.F.R. §164.408 as aggravating factors.
Second, OCR considered the nature and extent ofthe harm resulting from the violation. JHS
identified two employees who in July 2015 accessed the PHI ofa NFL player patient without a
job related reason to do so. Subsequently, the NFL player's PHI from his treatment at JHS was
disclosed by multiple media outlets, including by an ESPN reporter via Twitter. Due to the leak
ofthe NFL player's medical condition, he suffered financial and reputational harm. He suffered
an injury to his hand which threatened his reputation as a successful football player.
Additionally, the New York Giant's football team rescinded a $60 million contract offer after the
ESPN tweet was posted. Similarly, another JHS employee abused her access to PHI from 2011
to 2016 in JHS systems. She admitted in January 2016 to selling the PHI of2,000 JHS patients.
JHS discovered that she had accessed the PHI of24,189 individuals without a job related reason.
Page 9 of12
Third, OCR considered JHS's history of compliance. This action stems from investigations of
three different breaches reported in 2013, 2015 and 2016. Further, from 2012-2018, JHS filed
approximately 150 "under-500" breach reports. Approximately 391 individuals were affected
cumulatively by these ''under-500" breaches.
Fourth, OCR considered JHS 's financial condition. OCR is cognizant ofJHS's position as a public
entity that routinely serves low-income and disadvantaged patients. OCR has detennined that the
CMP amount will not affect JHS's ability to come into compliance or jeopardize its ability to
continue to provide health care for patients. JHS is a very large healthcare system with multiple
and diverse sources ofrevenue.
Fifth, OCR has considered JHS's cooperation during this investigation as well as voluntary steps
it has taken towards overall compliance. Such mitigating steps include implementing a HIP AA
policy manual, restricting physical access to sensitive areas and workstations, implementing
automatic logout procedures, appropriately sanctioning workforce members (termination),
retraining workforce members regarding identity theft, hiring key compliance personnel (Chief
Privacy Officer, Chief Information Security Officer), and purchasing activity review monitoring
software.
Lastly, by its Letter ofOpportunity, OCR offered JHS the opportunity to provide written
evidence ofmitigating factors within thirty (30) days from the date ofreceipt ofthat letter. As
noted in Paragraph II.47 above, JHS submitted its response to OCR by letter dated July 17, 2019,
which did not provide any written evidence ofmitigating factors for consideration under
§ 160.408. Instead, JHS's response merely referenced the "correspondence" previously provided
to OCR "over the past several years."
Accordingly, as stated in the preceding paragraphs ofthis section, OCR has considered mitigating
factors in determining the amount ofthe CMP. Therefore, despite the evidence ofharm to affected
individuals and extended nature of the violations, OCR continues to use the lowest amount in the
reasonable cause tier, $1,000 ($1,141 after November 2, 2015), for purposes of calculating the
penalties for violations under 45 C.F.R. § 164.308(a)(l) (security management process), and 45
C.F.R. §164.308(a)(4) (information access management).
VI.
Waiver
OCR has determined that there is no basis for waiver ofthe proposed CMP amount as set forth at
45 C.F.R. § 160.412. JHS presented no evidence that the payment ofthe CMP would be excessive
relative to the violations found here and described in OCR's letter to JHS ofJune 17, 2019.
VII.
Amount of CMP
A. Amount of CMP Per Violation
Based on the above factors, OCR finds that JHS is liable for the following CMPs for each violation
described in Section III:
Page 10of12
1. Security Management Process -
45 C.F.R. §164.308(a)(l): The CMP is
$326,000 (see attached chart - Appendix A). This CMP amount is based on 45
C.F.R. § 160.404(b)(2)(ii).
2. Infonnation Access Management - 45 C.F.R. §164.308(a)(4): The CMP is
$328,000 (see attached chart - Appendix A). This CMP amount is based on 45
C.F.R. § 160.404(b )(2)(ii).
3. Notice to the Secretary - 45 C.F.R. §164.408: The CMP is $1,500,000 (see
attached chart - Appendix A). This CMP amount is based on 45 C.F.R. §
160.404(b )(2)(ii).
B. Total Amount of CMP
The total amount ofCMPs for which OCR finds JHS liable, with regard to the violations described,
is $2,154,000 (see attached chart - Appendix A).
VIII. Right to a Hearing
JHS has the right to a hearing before an administrative law judge to challenge these proposed
CMPs. To request a hearing to challenge these proposed CMPs, you must mail a request, via
certified mail with return receipt request, under the procedures set forth at 45 C.F.R. Part 160
within 90 days of your receipt of this letter. Such a request must: (1) clearly and directly admit,
deny, or explain each ofthe findings offact contained in this notice; and (2) state the circumstances
or arguments that you allege constitute the grounds for any defense, and the factual and legal basis
for opposing the proposed CMPs. See 45 C.F.R. § 160.504(c). Ifyou wish to request a hearing,
you must submit your request to:
Department ofHealth & Human Services
Departmental Appeals Board, MS 6132
Civil Remedies Division
330 Independence Ave, SW
Cohen Building, Room G-644
Washington, D.C. 20201
Telephone: (202) 565-9462
Copy to:
Serena Mosley-Day, Senior Advisor
Office for Civil Rights
200 Independence Avenue, SW
Suite 523E
Hubert H. Humphrey Building
Washington, D.C. 20201
Telephone: (404) 562-7864
A failure to request a hearing within 90 days permits the imposition ofthe proposed CMPs without
Page 11 of12
a right to a hearing under 45 C.F.R. § 160.504 or a right ofappeal under 45 C.F.R. § 160.548. If
you choose not to contest this proposed CMP, you should submit a written statement accepting its
imposition within 90 days ofreceipt ofthis notice.
IfJHS does not request a hearing within 90 days, then OCR will notify you of the imposition of
the CMPs through a separate letter, including instructions on how you may make payment, and
the CMPs will become final upon receipt ofsuch notice.
Ifyou have any questions regarding this matter, please contact Serena Mosley-Day, Senior Advisor
for Compliance and Enforcement at (404) 562-7864 or at serena.mosley-day@hhs.gov.
Sincerely,
ievh-<--~
\
Timothy Noonan
Regional Manager
Office for Civil Rights
Enclosures -
Appendix A: CMP Penalty Chart
Page 12 of12
·,~~::~::
~ .;;·,•.: >:~· ~ ..~~:.'. ~'/~~~.. •'•:I
··~ ·~r.~·J: ' :.rP.n~l<L~llill;i :nn.~....,--;~ , •
.,,.1~.lr.•tal•· \t!.tl ...~..1r1: Irj"L:IJ~qf!.l 1
.....
~•i"'--....,.'"""-,,,,,.-,...,,.·~ .
'- ~-
#ofdays
Applicable
Compliance Fai lure
Post-HITECH
Beginning
End Date
Occurrence
based on
Amount
Actual Penalty
Calendar Year Adjusted Total
Penalty Tier
Date
365 day
Cap
year
Reasonable Cause
7/22/2013
12/31/2013
Daily
163
$1 ,000
$163,000
$100,000
$100,000
Security Management
Reasonable Cause
1/1/2014
12/31/2014
Daily
365
$1,000
$365,000
$100,000
$100,000
Reasonable Cause
l/1/2015
11/2/2015
Daily
306
$1 ,000
$306,000
$100,000
Process
Reasonable Cause
11 /3/2015
12/31/2015
Daily
59
$1 ,000
$59,000
$100,000
$100,000
Reasonable Cause
l/1/2016
1127/2016
Daily
26
$1,000
$26,000
$100,000
$26,000
Total Days
919
$919,000
Sub-Total
$326,000
Reasonable Cause
7/22/2013
12/31/2013
Daily
163
$1,000
$163,000
$100,000
$100,000
Information Access
Reasonable Cause
l/1/2014
12/31/2014
Daily
365
$1,000
$365,000
$100,000
$100,000
Management
Reasonable Cause
11112015
11/2/2015
Daily
306
$1,000
$306,000
$100,000
$100,000
Reasonable Cause
11/3/2015
12/31/2015
Daily
59
$1,000
$59,000
$100,000
Reasonable Cause
1/1/2016
1/29/2016
Daily
28
$1,000
$28,000
$100,000
$28,000
Total Days
921
$921,000
Sub-Total
$328.000
Notice to HHS
Willful Neglect
7/22/2013
8/22/2013
Daily
31
$50,000
$1,550,000
$1,500,000
$1,500,000
Total Days
31
Sub-Total
Sl ,500,000
Total Uncapped:
$3,390,000
Total Capped:
$2,154,000