Cyber
While hackers are awaiting an opportunity, noncompliance and the impacts caused by this is an unacceptable situation. Some industries have more risk due to the sensitive information they deal with, and thus require tighter security regulations. Hence organizations tailor their security policies and mandates employees to follow the same. Unauthorized access to data is very restricted in case of healthcare organizations, and usually employees are expected to follow the policy of not accessing organizational data even though they were former users to the application. A Colorado hospital has been fined with $111,400, since they have failed to terminate the employeesʼ access to a
web-based scheduling calendar. This unauthorized access resulted in disclosure of 557 patientsʼ ePHI. A former employee of PSMC continued to have remote access to a web-based scheduling calendar even after leaving the organization. The employee seemed to have accessed the calendar on two different occasions. PMSC had to pay the fine and in addition to that, they had to submit annual reports to HHS on if they are meeting the compliance regulations. The case inevitably shows the policy violation by an ex-employee whereas they are not supposed to misuse the access privileges while they are no more working in the organization.
Reference: hipaajournal. (2018, December 12). Failure to Terminate Former Employeeʼs PHI Access Costs Colorado Hospital $111,400. Retrieved from https:// www.hipaajournal.com/ failure-to-terminate- former-employees-phi- access-costs-colorado- hospital-111400/