article thumbnail

Settlement Reached in Excellus HIPAA Class Action Lawsuit

Compliancy Group

In September 2015, Excellus filed a breach report with the OCR, disclosing that cybercriminals had free access to patient files containing electronic protected health information (ePHI) from December 2013 through May 2015. Developing strategies to ensure records containing PHI are disposed of within one year of the original retention period.

HIPAA 52