Can you sue over hipaa violations
On the other hand, disclosures of certain medical procedures might be highly offensive. Consider whether an invasion of privacy claim is available. Craig Painter. All Rights Reserved. Powered by. Client Login. Thank you for contacting us. Not all cases will qualify for civil suits, however. They realize their mistake and promptly close it again. They do nothing with the small amount of information they encountered.
This is a prime example of a very mild incident. Likewise, accidental breaches that were unavoidable will also cause no harm and garner only minor responses.
More severe incidents can take several forms. They may affect a large number of patients or they may affect a small number of patients in a dramatic way. They may have been preventable if proper care had been taken, or they may have been an intentional abuse of power. Entities that respond per legal standards can absolve themselves of liability. Entities that do not respond to legal standard can open themselves up to shared liability.
For instance, an individual worker committing violations is liable for their own actions. The degree to which they are liable can vary, depending on:. For example, a health care worker who accidentally accessed files they should not have seen did commit a violation.
But that violation was small and unintentional. Their liability is much lower than that of a similar worker who intentionally and repeatedly:. At the same time, the organization for which an employee works can also be liable. How it responds to an incident can mitigate or inflate that responsibility.
This is most likely to happen when:. If possible, this is the best route to take. Victims may also choose not to bring civil cases even in situations where they could. Most often this is because the costs of the case would outweigh any potential awards.
When suing an individual health care worker, victims may find that defendants do not have much in the way of assets. Even if they win their case, there is little to gain. Organizations will mete out punishments such as stripping violators of their right to work in the health care field and their medical credentials. They will terminate employees where appropriate. If filing a complaint in writing, you should use the official OCR complaint form and should keep a copy to provide to your legal representative.
You can find attorneys through your state or local bar association. Try to find an attorney or law firm well versed in HIPAA regulations for the greatest chance of success and contact multiple law firms and speak with several attorneys before making your choice. There will no doubt be many other individuals who are in the same boat, some of whom may have already taken legal action. Joining an existing class action lawsuit is an option.
The more individuals involved, the stronger the case is likely to be. Many class action lawsuits have been filed on behalf of data breach victims that have yet to experience harm due to the exposure or theft of their data. The plaintiffs claim for damages for future harm as a result of their data being stolen.
However, without evidence of actual harm, the chances of success will be greatly reduced. Author: Steve Alder has many years of experience as a journalist, and comes from a background in market research.
0コメント