The University of Rochester Medical Center (URMC) will pay a $3 million penalty to the Department of Health and Human Services’ Office for Civil Rights (OCR), wrapping up two investigations into potential patient privacy violations which began in 2013 and 2017 respectively. 

URMC voluntarily filed the violations after failing to adhere to Health Insurance Portability and Accountability Act (HIPAA) privacy and security rules, first by losing protected health information on an unencrypted flash drive, and next by losing an unencrypted laptop with similar sensitive data. 

OCR’s investigation ruled that URMC has made an insufficient effort to minimize the risks to personal data being shared, and that the medical center lacked a comprehensive risk action plan. Part of the settlement agreement mandates that URMC undergo a risk analysis and develop and implement a risk management plan. 

The U.S. Department of Health and Human Services’ (HHS) press release referenced a 2010 incident when URMC was investigated after reporting a lost unencrypted flash drive, saying that URMC “permitted the continued use of unencrypted mobile devices” despite being aware of the risks involved.   

Director of external communications for URMC Chip Partner says this is incorrect. 

“Since 2010 it has been improper and against policy to store protected health information on an unencrypted device.” Partner said. He added that regarding the breaches, “the employees involved were in violation of that policy.”

In the future, Partner said, technological changes could be made to limit the ability of people to store private information on personal devices. 

“The medical center is deeply committed to protecting patient privacy, and we continuously improve our IT security safeguards and staff training to reduce the risk of a privacy breach,” Partner wrote in an email. He said in an interview: “We already believe that we have strong systems in place and we’re going to use this settlement to make them stronger.”

Tagged: URMC


URMC to pay $3 million for privacy violation

The Yellowjackets scored a near victory against the Rensselaer Polytechnic Institute (RPI) Engineers in women’s lacrosse April 18. The game ended in a very close 10–9 win that was entertaining to all watching. Read More

URMC to pay $3 million for privacy violation

In anticipation of 2026’s graduation ceremony, the Campus Times conducted an interview with upcoming Commencement speaker Jeannine Shao Collins ’86. Collins, who earned a bachelor's degree in economics from URochester, currently works as the Chief Client Officer at Kargo: a multiplatform advertising and media company. Read More

URMC to pay $3 million for privacy violation

The first realization of my own age hit me in the months before I started college. I was helping my dad clean the small office he’d occupied in Rush Rhees longer than I’d been alive. The walls of which boasted childhood drawings that my sister and I had crayoned. Even though I was looking at my distant past, I realized I would soon be starting a new page of my future. Read More