Healthcare IT NewsHealthcare IT News
TwitterFacebookLinkedInHealthcareITNews International
  • Home
  • Topics
    • ARRA/Stimulus
    • Business Intelligence
    • Claims Processing
    • Data Warehousing
    • EDIS
    • Election 2012
    • Electronic Health Records
    • Enterprise Content Management
    • Enterprise Resource Planning
    • ePrescribing
    • Financial/Revenue Cycle Management
    • Health Information Exchange (HIE)
    • ICD-10
    • Mobile/Wireless
    • Network Infrastructure
    • Policy and Legislation
    • Privacy and Security
    • Quality and Safety
    • RIS and PACS
    • RTLS
    • Telehealth
    • Workforce Management
  • Issues
    • January 2012
    • December 2011
    • November 2011
    • October 2011
    • September 2011
    • August 2011
  • Webinars
    • Upcoming Webinars
    • On Demand Webinars
  • White Papers
  • Blog
  • Events
  • HIMSS JobMine
  • RSS
  • Press Releases
  • Slideshows
  • Videos
  • Podcasts
  • Supplements
  • Survey Analyses
  • Newsletters
  • Advertise
  • Login
  • Register
  • SUBSCRIBE
    • Newspaper
    • Email Newsletter
Home » News » Privacy and Security
Receive News By Email

  • del.icio.us
  • Digg
  • StumbleUpon
  • Reddit
  • Facebook
  • Google
  • RSS Icon
  

Rite Aid to pay $1M for HIPAA privacy breaches

July 29, 2010 | Mary Mosquera, Contributing Editor

Suggested Content

  • Mass General pays $1M to settle potential privacy violations
  • HHS issues rule on EHR breach notification
  • Veterans Affairs CIO Roger Baker on VLER progress
  • HHS names Rodriguez chief health data privacy enforcer
  • Beacon Communities snag more money for IT
  • HHS unveils proposed regs for state insurance exchanges
  • HHS unveils proposed health insurance exchange regs
  • Docs tell government panel EHR tales of woe
  • HHS aims to fund state efforts against Medicaid fraud

Related Resources

  • Securing Hospital and Health Networks: a Case Study on Sarasota Memorial Health Care System
  • Learn to Optimize Your Radiology Department & Drive Productivity
  • Taking a Framework Approach to Securing Electronic Health Records (EHRs)
  • An IDC Health Insights and Intel Webcast: mHealth and The Second Wave of Clinical Mobility
  • IBM with IDC Health Insights: Exploring the HITECH Act for Privacy and Security of Personal Health Information

WASHINGTON – Rite Aid Corp. has agreed to pay $1 million to settle potential violations of federal privacy rules when the national pharmacy chain failed to protect sensitive customer information in disposing of prescriptions and pill bottles in store trash containers.

The settlement followed enforcement of the privacy rule of the Health Insurance Portability and Accountability Act (HIPAA) by the Department of Health and Human Services. In a coordinated action, Rite Aid signed a consent order with the Federal Trade Commission (FTC) to settle potential violations of the FTC Act, HHS said in an announcement July 27.

HHS' Office of Civil Rights, which oversees health information privacy, and FTC collaborated on the investigation after television news media videotaped incidents when Rite Aid employees threw out pill bottles with individuals' health information on the labels in dumpsters that were accessible to the public, said OCR director Georgina Verdugo.

As part of the agreement, Rite Aid and its 4,800 pharmacies will establish policies and employee training policies on how to protect sensitive information and obtain independent assessment of pharmacy compliance with the HIPAA privacy rule.

"We hope that this agreement will spur other health organizations to examine and improve their policies and procedures for protecting patient information during the disposal process," Verdugo said in a statement.

Verdugo said the drug store chain began increasing employees' awareness of the company's privacy policy and making sure that they were disposing of patient information correctly. Confidential information is put into specific color bags and sent to special distribution centers and it's destroyed there, she said.

Rite Aid spokeswoman Cheryl Slavinsky said, "We take this very seriously. We are not aware of any harm to customers or patients from the investigated incidents, and we certainly hope that it does not happen again."

Rite Aid has strengthened HIPAA program training with better tracking and monitoring to make sure employees read policies and perform the computer-based training modules, she said.

This is the second joint investigation and settlement conducted by OCR and FTC. In February 2009, CVS, another national drug store chain, agreed to pay a $2.25 million fine and establish similar improvements in its internal practices.

The HIPAA Privacy Rule requires health plans, health care clearinghouses and most health care providers, including most pharmacies, to safeguard the privacy of patient information, including such information during its disposal.

Related Topics:
  • Department of Health and Human Services
  • Federal Trade Commission
  • Georgina Verdugo
  • Mary Mosquera
  • OCR
  • Rite Aid Corp.
  • Washington
  • Privacy and Security

Reader Comments (1)Login to Post a Comment

Kristen says: Medicine bottle had old label from another patient under mine
July 29, 2010 | 12:16PM GMT

I got a bottle of prescription cough syrup last Fall from Rite Aid and it had an old label under mine that had another patient's info it. It was for a guy that lives in my town. The other patient probably never picked it up and they recycled the bottle and just stuck my label on top of the other.

Most Popular

Latest Headlines
Most Popular
  • 10 most outlandish kinds of ICD-10 codes
  • 5 stages of EHR maturity and patient collaboration
  • Megaupload: Lessons Learned in Cloud Computing Risks
  • 5 issues affecting cloud service quality and performance
  • 'Obamacare' a lightning rod, but what about health IT?
  • Demand exceeds supply for some health IT jobs
  • Arkansas selects OptumInsight for statewide HIE
  • Vocal against health reform, Missourians quiet on health IT
  • 5 simple ways to realize ROI from your EHR
  • Maine receives grant to connect behavioral healthcare to HIE

WEBINARS AND WHITE PAPERS

  • WHITE PAPERS
    Sharp HealthCare: Growing Content Management into an Enterprise Strategy
  • WHITE PAPERS
    Driving Meaningful Use of Enterprise Content Management
  • ON DEMAND WEBINARS
    Case Study: Sentara Healthcare Completes an Award-Winning EHR with Enterprise Content Management
  • WHITE PAPERS
    The Christ Hospital Case Study: Improving Operations and Ensuring the Best Possible Patient Care with ECM
  • WHITE PAPERS
    Winning the EHR Battle with Enterprise Content Management
More Resources
Syndicate content

HIMSS JOBMINE

  • Director, Sales - HIMSS - Arlington, VA
  • Program Analyst - Mathematica Policy Research - Princeton, NJ
  • Oracle Implementation Analyst - Virginia Mason Medical Center - Seattle, WA
  • Web and Custom Development Manager - Virginia Mason Medical Center - Seattle, Washington
  • Epic Analyst/Builder - Vitalize Consulting Solutions - Nationwide
more jobs

Marketplace

Follow Healthcare IT News on TwitterFan Healthcare IT News on FacebookJoin Healthcare IT News on LinkedInRSS Subscriptions
Digital EditionBlogEvents
JobsMobile SiteMobile App
 
Healthcare Finance News Government Health IT EHRWatch Healthcare Payer News HITECHWatch ICD10Watch mHIMSS PhysBizTech NHINWatch
©2012 MedTech Media Healthcare IT News is a publication of MedTech Media
Subscribe Advertise About Us Privacy Policy