Court Rules
All enforcement actions
SettlementHigh Risk

Cottage Health System Fined $2M for Medical Data Security Failures

Cottage Health SystemNovember 22, 2017California Attorney General

Penalty Amount

$2,000,000

Summary

Cottage Health System experienced two data breaches exposing medical information of over 50,000 patients due to inadequate security measures. The settlement requires a $2 million penalty and upgrades to security practices, including designating a Chief Privacy Officer.

Remedy

Cottage Health must pay $2 million, implement and maintain reasonable security practices for patient information, designate a Chief Privacy Officer, and conduct periodic risk assessments.

Monetary PenaltyCompliance ProgramAudit Requirement

Contract Impact

In-house legal teams should review all agreements involving protected health information (PHI), including Business Associate Agreements (BAAs) with vendors, patient consent and service agreements, and employee confidentiality/access agreements. Focus on clauses specifying data security standards (encryption, access controls), breach notification timelines and responsibilities, audit rights, and requirements for risk assessments. Given the settlement's mandate for a Chief Privacy Officer and security upgrades, contracts may need amendments to explicitly require these roles/procedures, mandate regular security audits, enforce specific technical safeguards, and clarify liability for inadequate protection of medical data.

Contract Search Terms

data security requirementsencryption standardsbreach notification proceduresHIPAA compliance obligationsthird-party vendor managementrisk assessment clausesincident response planChief Privacy Officer designationpatient data access controlssecurity audit provisions

Laws Cited

California Confidentiality of Medical Information ActCalifornia Unfair Competition LawHealth Insurance Portability and Accountability Act (HIPAA)

Violation Types

Entity Details

Entity

Cottage Health System

Industry

Healthcare

Official Sources

Related Enforcement Actions

CA

Paramount Skydance Corporation

A coalition of 12 state attorneys general, led by Colorado AG Phil Weiser, obtained a temporary restraining order from a federal court in California to halt the proposed $110 billion merger of Warner Bros. Discovery, Inc. by Paramount Skydance Corporation. The lawsuit alleges the merger violates Section 7 of the Clayton Act by substantially lessening competition in film distribution, anticipated blockbuster film distribution, and licensing cable TV channels.

CA

California Privacy Protection Agency

The California Privacy Protection Agency (CalPrivacy) joined a coalition of 18 Attorneys General and state agencies in opposing the proposed SECURE Data Act, a federal privacy bill that would preempt stronger state privacy laws like the CCPA. The coalition argues the bill would weaken consumer privacy protections, limit enforcement remedies, and undermine California's Delete Request and Opt-out Platform (DROP).

CA

General Motors

$12.8M

California Attorney General Rob Bonta, along with multiple district attorneys and the California Privacy Protection Agency, announced a $12.75 million settlement with General Motors for illegally selling hundreds of thousands of Californians' location and driving data to data brokers Verisk and LexisNexis without notice or consent. The settlement includes the largest CCPA penalty to date, a five-year ban on selling driving data to consumer reporting agencies, and requirements to delete retained data and implement a robust privacy program.

CA

California Privacy Protection Agency

The California Privacy Protection Agency Board voted to support two bills (AB 1542 and SB 1106) and took a 'support if amended' position on a third bill (AB 883). These bills aim to strengthen privacy protections by expanding sensitive data protections, improving deletion rights under the Delete Act, and providing expedited deletion for elected officials and judges.

CA

California Privacy Protection Agency

The California Privacy Protection Agency sent a letter to Congress opposing the SECURE Data Act, a federal bill that would preempt state privacy laws like the CCPA and Delete Act. The letter argues the bill would eliminate rights for 40 million Californians, including the DROP platform and opt-out preference signal requirements, and urges Congress to set a floor rather than a ceiling on privacy protections.

CA

Nexstar Media Group, Inc. and Tegna Inc.

California Attorney General Rob Bonta, joined by attorneys general from seven other states, filed a lawsuit to block the $6.2 billion merger between Nexstar Media Group and Tegna Inc. The lawsuit alleges the merger violates Section 7 of the Clayton Act by reducing competition in local TV markets, leading to higher prices, less local news, and job losses.