Photo: Shutterstock.com

A large provider of products and services to people with chronic and acute kidney disease has agreed to pay $3.5 million to the federal government after five separate low-tech data breaches in 2012, the U.S. Department of Health and Human Services has announced.

In addition to the monetary settlement, Fresenius Medical Care North America agreed to adopt a comprehensive corrective action plan to settle potential violations of the Health Insurance Portability and Accountability Act Privacy and Security rules that were identified by HHS's Office for Civil Rights.

Fresenius is a German-based company with a North American unit that serves more than 170,000 patients in the United States through a network of dialysis facilities and outpatient lab.

The company reported five separate incidents that occurred between February and July 2012 that breached electronic protected health information of patients at five of its facilities. The incidents involved the theft or loss of laptop and desktop computers or USB drives storing confidential patient data.

An ensuing investigation found that the facilities failed to conduct an accurate and thorough analysis of potential risks and vulnerabilities to the data, and impermissibly disclosed patients' protected information by providing unauthorized access for a purpose not permitted by HIPAA, according to HHS.

OCR Director Roger Severino said in a statement, “The number of breaches, involving a variety of locations and vulnerabilities, highlights why there is no substitute for an enterprise-wide risk analysis for a covered entity. Covered entities must take a thorough look at their internal policies and procedures to ensure they are protecting their patients' health information in accordance with the law.”

A Fresenius North America spokesman said that there is no evidence that any of its patients' health information was improperly accessed or misused. The settlement is not an admission of any HIPAA violation, the statement said.

“We take the protection of our patients' health information very seriously,” the statement continued. “It is a top priority for our company and a critical issue facing the entire health care industry. We have and will continue to take additional steps to protect patient data. We strive to enhance security, better train staff and reduce incidence of equipment theft.”

According to HHS, the breaches occurred at Fresenius facilities in Jacksonville, Florida; Semmes, Alabama; Maricopa, Arizona; Augusta, Georgia; and Blue Island, Illinois.

The corrective action plan requires the facilities to complete a risk analysis and risk management plan, revise policies and procedures on device and media controls as well as facility access controls, and to develop an encryption report and educate its workforce on policies and procedures, HHS said.

The agreement was signed by Susan Pezzullo Rhodes, HHS New England regional manager for the Office for Civil Rights, and Louise Bucolo Sr., director of privacy and information security, Fresenius Medical Care North America.