Violation Tracker Individual Record

Company: 
University of Rochester Medical Center
Current Parent Company: 
University of Rochester Medical Center
Penalty: 
$3,000,000
Year: 
2019
Date: 
November 5, 2019
Offense Group: 
consumer-protection-related offenses
Primary Offense: 
privacy violation
Violation Description: 

The University of Rochester Medical Center agreed to pay $3 million to the HHS Office for Civil Rights and take substantial corrective action to settle potential violations of the Health Insurance Portability and Accountability Act (HIPAA) Privacy and Security Rules.

Level of Government: 
federal
Action Type: 
agency action
Agency: 
Health & Human Services Department Office for Civil Rights
Civil or Criminal Case: 
civil
Facility State: 
New York
Facility City: 
Rochester
HQ Country of Parent: 
USA
HQ State of Parent: 
New York
Ownership Structure of Parent: 
non-profit
Major Industry of Parent: 
healthcare services
Specific Industry of Parent: 
hospitals
Source Notes: 
If an online information source is not working, check the Violation Tracker Data Sources page for an updated link.
Parent company note: 
Parent-subsidiary relationship is current as of the most recent revision listed in the Update Log.