The MD Anderson Breach: What Three Unencrypted Devices Cost a Cancer Center

FH47 - MD Anderson Blog

A stolen laptop. Two lost USB drives. 33,500 patient records. A $4.3 million fine. And a warning the organization had already given itself years earlier.

Between 2012 and 2013, the University of Texas MD Anderson Cancer Center reported three separate data breaches to the U.S. Department of Health and Human Services. Each one involved an unencrypted portable device. Each one was preventable. And together, they became one of the most cited HIPAA enforcement cases in healthcare data security history.

 

What happened

The first incident occurred in April 2012, when a laptop was stolen from the home of an employee who had been working remotely. The laptop had been purchased with organizational funds. It was not encrypted and was not password protected. It contained the electronic protected health information of 29,021 patients, including names, Social Security numbers, medical record numbers, and treatment and research information.

Three months later, in July 2012, an employee lost an unencrypted USB thumb drive while riding one of the organization’s shuttle buses. The drive contained the protected health information of 2,264 patients.

In November 2013, a visiting researcher lost a second unencrypted USB thumb drive. It contained the protected health information of approximately 3,598 patients, including names, dates of birth, medical record numbers, and diagnoses.

In total, the three incidents exposed the records of more than 33,500 individuals.

 

The detail that made it worse

The cancer center had known since 2006 that encryption was necessary. Its own annual risk analysis had identified the failure to encrypt devices as a high-risk concern for years before any of these incidents occurred.

The organization had adopted a policy requiring encryption of devices containing patient data. What it had not done was implement that policy. The HHS Office for Civil Rights noted that the cancer center’s own internal teams had been raising the need for encryption for years before any of the breaches occurred.

Mass encryption of devices did not begin until 2012, after the first breach had already occurred.

 

The regulatory response

The HHS Office for Civil Rights investigated all three incidents and in 2018, an administrative law judge issued a summary judgment in favor of OCR on all issues, requiring the cancer center to pay $4,348,000 in civil monetary penalties.

The cancer center appealed. In 2021, the U.S. Court of Appeals for the Fifth Circuit overturned the financial penalty. The court found that covered entities are not required to have bulletproof protections for safeguarding electronic protected health information. The fine was vacated.

However, the legal outcome did not change the factual record. Three devices left the organization containing unencrypted patient data. The data on those devices was accessible to anyone who found or took them.

 

What Opal Lock would have changed

With hardware encryption configured on the laptop through a compatible TCG Opal self-encrypting drive, the drive would have required authentication before any data could be read, regardless of which machine it was connected to. Removing the laptop from the employee’s home and connecting it elsewhere would have returned nothing. The encryption holds at the drive controller level independently of any operating system.

For the USB drives, the same principle applies. An Opal-compatible USB drive set up through Opal Lock requires credentials to access. A lost or found drive without those credentials is unreadable.

Pre-boot authentication on the laptop, available on Opal Lock Standard and Premium editions, would have required the employee to authenticate before the operating system loaded. Without that credential, the data on the drive would have been inaccessible regardless of what happened to the device after it left the house. For USB drives, Opal Lock USB covers external USB-mounted Opal drives with the full setup, lock, unlock, and sanitization workflow.

 

The compliance cost beyond the fine

The fine was eventually overturned. The breach was not.

More than 33,500 patients had their names, Social Security numbers, medical records, and treatment information exposed. The cancer center spent years in regulatory investigation and litigation. Its internal encryption programme, which had been identified as necessary years earlier, was accelerated by the breach rather than before it.

The cost of implementing encryption before an incident is a fraction of the cost of managing the consequences after one. The lesson from this case is not that fines are inevitable. It is that the gap between knowing encryption is necessary and actually implementing it is where breaches happen.

Compare Opal Lock editions at fidelityheight.com/shops/

 

Sources: HHS Office for Civil Rights, Healthcare IT News, HIPAA Journal, Healthcare Dive, Texas Public Radio, SGR Law — 2018 and 2021

Ready to buy

Secure your drives. Buy your license now.

Activate hardware encryption on compatible Opal drives in minutes. Select your edition and complete purchase below.