Behavioral Health Resources has agreed to a $1.1 million settlement following a significant data breach that compromised the personal and health information of thousands of patients. The breach, which was traced back to insufficient security measures and delayed breach notification, raised serious concerns about compliance with the Health Insurance Portability and Accountability Act (HIPAA). Authorities emphasized that the organization failed to implement adequate safeguards, leading to unauthorized access to sensitive behavioral health records.

In addition to the settlement payment, the agreement requires Behavioral Health Resources to enhance its data protection protocols. Key measures include:

  • Comprehensive risk assessments and regular security audits
  • Mandatory employee training on data privacy and breach response
  • Implementation of advanced encryption and multi-factor authentication
  • Development of an incident response plan to ensure timely notifications
Settlement Details Information
Amount $1.1 million
Number of Patients Affected Over 20,000
Data Types Exposed PHI, Mental Health Records, Contact Info
Deadline for Compliance 12 months from settlement