• Skip to main content
  • Skip to main content
Choose which site to search.
University of Arkansas for Medical Sciences Logo University of Arkansas for Medical Sciences
Research and Innovation: Institutional Review Board
  • UAMS Health
  • Jobs
  • Giving
  • About
    • Compliance Statement
    • Full Board Meetings
      • Committee Rosters
    • Institutional Review Board Blogs
    • Institutional Review Board Staff
    • Join the UAMS Institutional Review Board
    • Review Fees
  • CLARA
    • Access the System
    • Request a Human Subjects Research Determination
    • Start a Study
  • Templates, Training and Tools
    • Consent for Non-English Speakers
    • Events and Deviations Tables
    • Expanded Access Programs: Compassionate Use & Emergency Use
    • Human Subject Protection Training Instructions
  • Reporting to the Institutional Review Board
  • Expanded Access
  • Institutional Review Board Policies
    • Current Institutional Review Board Policies
      • 1 Principles and Authority
      • 2 Relationships
      • 3 Committee Membership
      • 4 Institutional Review Board Operations
      • 5 Records (Retired)
      • 6 Documentation
      • 7 Procedures for Study Review
      • 8 Change in Protocol
      • 9 Institutional Review Board Decisions
      • 10 Principal Investigator Responsibilities
      • 11 Appeals and Reconsiderations (retired)
      • 12 Quality Assurances
      • 13 Confidentiality
      • 14 Recruitment Practices
      • 15 Consent
      • 16 Risk / Benefit Analysis (moved)
      • 17 Special Populations
      • 18 Drugs and Devices
      • 19 Human Genetics Guidance
      • 20 Questions, Concerns, Suggestions and Complaints
    • Institutional Review Board Policy Archives
      • 1 Principles and Authority Archive
      • 2 Relationships Archive
      • 3 Committee Membership Archive
      • 4 Institutional Review Board Operations Archive
      • 5 Records Archive
      • 6 Documentation Archive
      • 7 Procedures for Study Review Archive
      • 8 Change in Protocol Archive
      • 9 Institutional Review Board Decisions Archive
      • 10 Principal Investigator Responsibilities Archive
      • 11 Appeals and Reconsiderations Archive
      • 12 Quality Assurances Archive
      • 13 Confidentiality Archive
      • 14 Recruitment Practices Archive
      • 15 Consent Archive
      • 16 Risk / Benefit Analysis Archive
      • 17 Special Populations Archive
      • 18 Drugs and Devices Archive
      • 19 Human Genetics Guidance Archive
      • 20 Questions, Concerns, Suggestions, Complaints Archive
  • Research Resources
    • Acronyms and Resources
    • FAQs
      • CITI Program FAQs
      • CLARA FAQs
      • Does my project need IRB review?
      • Prereview and Review Process FAQs
      • Reporting FAQs
      • Submission FAQs
    • Single / Central Institutional Review Board Review
  • Human Research Protection Program Plan
  1. University of Arkansas for Medical Sciences
  2. Research and Innovation
  3. Institutional Review Board
  4. $4.3 million HIPAA penalty upheld for Texas cancer center

$4.3 million HIPAA penalty upheld for Texas cancer center

The theft of an unencrypted laptop and the loss of unencrypted thumb drives led to a $4.3 million fine levied against the MD Anderson Cancer in Texas recently. An administrative law judge recently upheld the determination and fine, according to the federal Office of Civil Rights (OCR).

The UAMS IRB tries to minimize the chances of this sort of incident by strongly, strongly, strongly encouraging study teams to use only institution-maintained hardware to store study data. Please store study data in UAMS- or ACH-maintained databases or laptops, and not on your personal devices. Also, while we strongly discourage the use of thumb drives in general for research because they’re so easy to lose, if you’re going to use one, please get one from your institution’s IT department that is encrypted.

The full text of the OCR’s news release is below. More information about the case, including the administrative law judge’s decision in all its great and gory detail, can be found at OCR’s website.

A U.S. Department of Health and Human Services Administrative Law Judge (ALJ) has ruled that The University of Texas MD Anderson Cancer Center (MD Anderson) violated the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy and Security Rules and granted summary judgment to the Office for Civil Rights (OCR) on all issues, requiring MD Anderson to pay $4,348,000 in civil money penalties to OCR. This is the second summary judgment victory in OCR’s history of HIPAA enforcement and the $4.3 million is the fourth largest amount ever awarded to OCR by an ALJ or secured in a settlement for HIPAA violations.

MD Anderson is both a degree-granting academic institution and a comprehensive cancer treatment and research center located at the Texas Medical Center in Houston. OCR investigated MD Anderson following three separate data breach reports in 2012 and 2013 involving the theft of an unencrypted laptop from the residence of an MD Anderson employee and the loss of two unencrypted universal serial bus (USB) thumb drives containing the unencrypted electronic protected health information (ePHI) of over 33,500 individuals. OCR’s investigation found that MD Anderson had written encryption policies going as far back as 2006 and that MD Anderson’s own risk analyses had found that the lack of device-level encryption posed a high risk to the security of ePHI. Despite the encryption policies and high risk findings, MD Anderson did not begin to adopt an enterprise-wide solution to implement encryption of ePHI until 2011 , and even then it failed to encrypt its inventory of electronic devices containing ePHI between March 24, 2011 and January 25, 2013. The ALJ agreed with OCR’s arguments and findings and upheld OCR’s penalties for each day of MD Anderson’s non-compliance with HIPAA and for each record of individuals breached.

“OCR is serious about protecting health information privacy and will pursue litigation, if necessary, to hold entities responsible for HIPAA violations,” said OCR Director Roger Severino. “We are pleased that the judge upheld our imposition of penalties because it underscores the risks entities take if they fail to implement effective safeguards, such as data encryption, when required to protect sensitive patient information.”

MD Anderson claimed that it was not obligated to encrypt its devices, and asserted that the ePHI at issue was for “research,” and thus was not subject to HIPAA’s nondisclosure requirements. MD Anderson further argued that HIPAA’s penalties were unreasonable. The ALJ rejected each of these arguments and stated that MD Anderson’s “dilatory conduct is shocking given the high risk to its patients resulting from the unauthorized disclosure of ePHI,” a risk that MD Anderson “not only recognized, but that it restated many times.”

Posted by Edith Paal on June 22, 2018

Filed Under: Research News

University of Arkansas for Medical Sciences LogoUniversity of Arkansas for Medical SciencesUniversity of Arkansas for Medical Sciences
Mailing Address: 4301 West Markham Street, Little Rock, AR 72205
Phone: (501) 686-7000
  • Facebook
  • X
  • Instagram
  • YouTube
  • LinkedIn
  • Pinterest
  • Disclaimer
  • Terms of Use
  • Privacy Statement
  • Legal Notices

© 2026 University of Arkansas for Medical Sciences