ZeroHour
CyberScooppublished ()ingested @HowellONeill

Medical supply giant Fresenius Medical Care fined $3.5 million for five data breaches

criticalData breach exploited in the wildimportance 60
Tagsbreach
Full article591 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

The list of violations is long, including a lack of necessary encryption and security policies.

cms breach
(Getty)

Medical supplies giant Fresenius Medical Care North America (FMCNA) agreed to pay $3.5 million to U.S. federal regulators after five separate data breaches in 2012.

The  U.S. Department of Health and Human Services Office for Civil Rights levied the fine along with a corrective action plan to settle potential violations of the Health Insurance Portability and Accountability Act (HIPAA) Privacy and Security Rules. A federal investigation found the company failed to conduct an accurate risk analysis of vulnerabilities to its protected information.

FMCNA filed five breach reports in January 2013 covering incidents from February-July 2012 impacting the electronic protected health information for five FMCNA-owned branches across the United States.

The list of violations is long. One branch didn’t encrypt sensitive information, another had no policies around removing hardware from facilities, two businesses had no safeguards against unauthorized access or theft while yet another had no procedure to address security incidents, according to the federal investigation.

“The number of breaches, involving a variety of locations and vulnerabilities, highlights why there is no substitute for an enterprise-wide risk analysis for a covered entity,” OCR Director Roger Severino said in a statement. “Covered entities must take a thorough look at their internal policies and procedures to ensure they are protecting their patients’ health information in accordance with the law.”

Fresenius Medical Care is a German-based international conglomerate that sells medical supplies around the world, with a concentration on kidney health. The company makes about $18 billion per year in revenue as of FY 2016.

FMCNA did not respond to a request for comment.

More Scoops

Sen. Bill Casssidy, R-La., questions Health and Human Services Secretary Robert Kennedy Jr. during a Senate Finance Committee at the Dirksen Senate Office Building on Sept. 4, 2025. (Photo by Andrew Harnik/Getty Images)

Bipartisan health care cybersecurity legislation returns to address a cornucopia of issues

The bill, first introduced late last year, deals with regulations, training, grants and more.

The headquarters of the Department of Health and Human Services in Washington, D.C., on Nov. 18, 2024. (Photo by ROBERTO SCHMIDT/AFP via Getty Images)

How HHS has strengthened cybersecurity of hospitals and health care systems

(Getty Images)

Stronger cyber protections in health care targeted in new Senate bill

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/fresenius-medical-care-data-breach-fines/