Lifespan Health System Affiliated Covered Entity, a Rhode Island nonprofit health system that is part of Lifespan Corp., agreed to pay $1.04 million to the HHS Office for Civil Rights.

The fine on Lifespan ACE was imposed by OCR to settle potential violations related to an unencrypted laptop that was stolen in 2017.
“Laptops, cell phones and other devices are stolen every day, that’s the harsh reality,” said OCR Director Roger Severino. “Entities can better protect data by encrypting their mobile devices to prevent identity theft.”
Lifespan Corp. reported a data breach to OCR in April 2017 when an employee’s personal computer was stolen from his car. The stolen laptop was unencrypted and contained emails that included patient names, medical record numbers, demographic information and medication information.
Lifespan Corp. said the data breach affected about 20,431 patients.

The OCR investigation found “systematic noncompliance with HIPAA rules,” including a failure to encrypt patient data on laptops and a lack of device control.
In addition to the fine imposed on it, Lifespan ACE will also implement other practices to ensure compliance with the rules.
A company spokesperson said there is no indication that patient data was breached or misused as a result of the incident.
“Lifespan takes these situations very seriously and deeply regrets what happened,” the statement said. “Both before the incident and over the past three years, we have taken numerous steps to further improve our practices to protect the security and confidentiality of patient information.” Last year, OCR fined the University of Rochester Medical Center $3 million after discovering multiple instances where devices with patient data were not encrypted.
