small-logo
ProfessionalsCapabilitiesInsights & NewsCareersLocations
About UsAlumniOpportunity & InclusionPro BonoCorporate Social Responsibility
Stay Connected:
facebookinstagramlinkedintwitteryoutube
  1. Privacy & Data Security

Blog

University of Washington Settles Potential HIPAA Violations for $750,000

  • PDFPDF
    • Email
    • LinkedIn
    • Facebook
    • Twitter
    Share this page
  • PDFPDF
    • Email
    • LinkedIn
    • Facebook
    • Twitter
    Share this page

Blog

University of Washington Settles Potential HIPAA Violations for $750,000

  • PDFPDF
    • Email
    • LinkedIn
    • Facebook
    • Twitter
    Share this page

1 Min Read

Author

Alessandra Swanson

Related Locations

Chicago

Related Topics

Health Care Privacy

Related Capabilities

Privacy & Data Security
Health Care

Related Regions

North America

January 12, 2016

The Office for Civil Rights (OCR) closed out 2015 by settling with University of Washington (UW) for $750,000 to address UW’s potential violations of the Health Insurance Portability and Accountability Act (HIPAA). OCR initially investigated UW after it reported a breach to the agency in November 2013. The breach occurred after a UW employee downloaded malware, which affected an IT system housing the protected health information of approximately 90,000 individuals. OCR’s ensuing investigation yielded evidence that UW had failed to ensure that all of its affiliated medical entities conducted risk analyses and implemented corresponding risk management plans, as required under HIPAA’s Security Rule.

While UW did not admit liability as part of the settlement, the Resolution Agreement between OCR and UW indicates that the settlement did not encompass potential HIPAA violations due to the breach itself, but rather centered on the potential Security Rule violations that were discovered during the investigation. UW also agreed to enter into a two-year monitoring period with OCR and to develop and implement an enterprise-wide risk analysis and risk management plan.

TIP: This settlement serves as a reminder that regulators may initiate an investigation based on one particular incident, but may expand their investigation – and pursue formal enforcement actions – based on other potential violations discovered during the investigation.

Related Professionals

Related Professionals

Alessandra Swanson

Alessandra Swanson

This entry has been created for information and planning purposes. It is not intended to be, nor should it be substituted for, legal advice, which turns on specific facts.

Logo
facebookinstagramlinkedintwitteryoutube

Copyright © 2025. Winston & Strawn LLP

AlumniCorporate Transparency Act Task ForceDEI Compliance Task ForceEqual Rights AmendmentLaw GlossaryThe Oval UpdateWinston MinutePrivacy PolicyCookie PolicyFraud & Scam AlertsNoticesSubscribeAttorney Advertising