• Contact
  • 888-54-FIRST
  • Client Login
    • Client Portal
    • Online Store
Search
First Healthcare Compliance
  • Solutions
    • Compliance Management Software
    • Online Compliance Courses
    • Compliance Management Suite
  • Plans
  • Resources
    • Blog
    • Virtual Education Hub
    • 1st Talk Compliance Podcast
    • Connect Magazine
    • Compliance Posters
    • Healthcare Compliance Books
    • Newsletter Signup
  • News & Events
    • Press Releases
  • Our Team
  • Request Demo
  • Menu Menu
  • Shopping Cart Shopping Cart
    0Shopping Cart

Blog

HIPAA Breach

A Costly Lesson in Untimely Reporting of a HIPAA Breach

March 9, 2017/in Blog, HIPAA

Presence St. Joseph Medical Center, a hospital of Presence Health Network, a large healthcare system serving Illinois, waited more than three months before it notified the Department of Health and Human Services (HHS) of a breach involving 836 individuals.  The untimely reporting cost the healthcare system $475,000 to settle with the HHS, including strict compliance with a 2-year corrective action plan that impacts all 150 locations of Presence Health Network. This costly lesson should serve as a reminder to all healthcare providers of the liability at stake if compliance measures are taken lightly.  

On January 31, 2014, Presence notified the HHS that it discovered a breach on October 22, 2013. Specifically, Presence uncovered that paper-based operating room schedules were missing from its facility, which contained PHI of 836 individuals in the form of individuals’ names, dates of birth, medical record numbers, dates of procedures, types of procedures, surgeon names, and types of anesthesia administered.

Under the HIPAA Breach Notification Rule, because the breach affected more than 500 individuals, Presence was required to notify the affected individuals, HHS, and major media outlets within 60 days of the breach. But it took Presence 101 days to report the breach to the government, citing miscommunication issues between staff for the delay.

HHS investigated the breach and found that Presence had not only untimely reported the breach to HHS, but also to those affected individuals and to media outlets; the affected 836 individuals were only notified on February 3, 2014 (104 days) and media outlets were only notified on February 5, 2014 (106 days). But the compliance issues did not end here.

HHS uncovered a pattern of delays during its investigation. HHS reviewed other breach events that occurred at Presence in 2015 and 2016. Since these breaches affected less than 500 individuals, the HIPAA Breach Notification Rule required notification to affected individuals within 60 days and notification to HHS within 60 days of the end of the calendar year. Yet again HHS learned that Presence failed to follow timely reporting requirements for these smaller breach events.

Presence’s compliance mistakes came with a hefty price tag. It also impacted its parent healthcare system via the corrective action plan that requires Presence Health Network to take immediate action in a number of areas to resolve weaknesses in its compliance program. Don’t put your organization on HHS’ radar— take time to review the effectiveness of your compliance policy, verify that your workforce is properly trained so they can take proper action, and make sure compliance policies are enforced. Otherwise, a government investigation may be in your future.

All breaches discovered in 2016 that affected fewer than 500 individuals were required to be reported by March 1, 2017. A breach report can be filed through the HHS Breach Portal here.

Tags: Breach, Health and Human Services, HHS, HHS Breach Portal, HIPAA, HIPAA breach
Share this
  • Share on Facebook
  • Share on X
  • Share on LinkedIn
  • Share on Reddit
  • Share by Mail
https://1sthcc.com/wp-content/uploads/2017/03/Untimely-Reporting-HIPAA.jpg 500 800 Catherine Short https://1sthcc.com/wp-content/uploads/2026/07/1stHCC_Logo_HORZ_LRG.png Catherine Short2017-03-09 12:00:002025-04-15 12:55:27A Costly Lesson in Untimely Reporting of a HIPAA Breach
You might also like
HIPAA Omnibus Final Rule and Your Practice
Ethics and HIPAA: Pivots, Guardrails, and Good Faith Ethics and HIPAA: Pivots, Guardrails, and Good Faith
OIG’s Updated Self-Disclosure Protocol
Data Privacy in 2021
Infographic: 6 Areas of Potential Liability for Healthcare Providers 6 Areas of Potential Liability for Healthcare Providers
Commemorate the 25th Anniversary of HIPAA with Educational Webinar with Rachel V. Rose

Subscribe to Weekly eNewsletter

Get the latest healthcare compliance updates straight to your inbox.

Subscribe to Newsletter

Recent Posts

  • The OIG Exclusions List: First Line of Employment Defense
  • Navigating the HIPAA Security Landscape: A Comprehensive Guide to Security Risk Assessments
  • OSHA Recordkeeping in Healthcare: Answers to Frequently Asked Questions
  • Naughty or Nice? The Rules of Giving and Receiving in Healthcare
  • fraud waste abuse healthcare compliance
    FWA in Healthcare: How to Respond Appropriately to Detected Offenses
  • Infographic: 6 Areas of Potential Liability for Healthcare Providers
    6 Areas of Potential Liability for Healthcare Providers

 

First Healthcare Compliance is a division of Panacea Healthcare Solutions. Learn more

Subscribe

Get the latest healthcare compliance updates straight to your inbox.

Subscribe to Newsletter

Connect

Get started: Request Demo

Call: 1-888-54-FIRST

E-mail: Contact us

  • Link to Instagram
  • Link to Youtube
  • Link to Facebook
  • Link to LinkedIn
  • Link to X
© Copyright 2026 Panacea Healthcare Solutions, LLC | Disclaimer | Privacy Policy and Copyright Notice
Scroll to top Scroll to top Scroll to top

We and our third-party partners use cookies to improve and personalize your experience on the site and with our services in addition to delivering and reporting on ads. Please visit our Privacy Statement for more information. By continuing to browse the site, you are agreeing to our use of cookies. Read Privacy Statement.

OKDismiss

Cookie and Privacy Settings



How we use cookies

We may request cookies to be set on your device. We use cookies to let us know when you visit our websites, how you interact with us, to enrich your user experience, and to customize your relationship with our website.

Click on the different category headings to find out more. You can also change some of your preferences. Note that blocking some types of cookies may impact your experience on our websites and the services we are able to offer.

Essential Website Cookies

These cookies are strictly necessary to provide you with services available through our website and to use some of its features.

Because these cookies are strictly necessary to deliver the website, refusing them will have impact how our site functions. You always can block or delete cookies by changing your browser settings and force blocking all cookies on this website. But this will always prompt you to accept/refuse cookies when revisiting our site.

We fully respect if you want to refuse cookies but to avoid asking you again and again kindly allow us to store a cookie for that. You are free to opt out any time or opt in for other cookies to get a better experience. If you refuse cookies we will remove all set cookies in our domain.

We provide you with a list of stored cookies on your computer in our domain so you can check what we stored. Due to security reasons we are not able to show or modify cookies from other domains. You can check these in your browser security settings.

Other external services

We also use different external services like Google Webfonts, Google Maps, and external Video providers. Since these providers may collect personal data like your IP address we allow you to block them here. Please be aware that this might heavily reduce the functionality and appearance of our site. Changes will take effect once you reload the page.

Google Webfont Settings:

Google Map Settings:

Google reCaptcha Settings:

Vimeo and Youtube video embeds:

Privacy Policy

You can read about our cookies and privacy settings in detail on our Privacy Policy Page.

Privacy Policy and Copyright Notice
Accept settingsHide notification only