If the health care industry was not yet sufficiently appreciative of the threats of cyberattacks, the $5.5 million penalty Advocate Health Care Network agreed to pay for violating data security measures gives hospitals, insurers and clinics another reason to get serious about securing their computer systems.

The U.S. Department of Health and Human Services reached a settlement with Advocate, which failed to “conduct an accurate and thorough assessment of the potential risks and vulnerabilities” of its electronic protected health information (ePHI).

The Illinois-based nonprofit health care network is the largest in the Land of Lincoln, and includes 12 hospitals and 250 treatment centers.

Recommended For You

Complete your profile to continue reading and get FREE access to BenefitsPRO, part of your ALM digital membership.

Your access to unlimited BenefitsPRO content isn’t changing.
Once you are an ALM digital member, you’ll receive:

  • Breaking benefits news and analysis, on-site and via our newsletters and custom alerts
  • Educational webcasts, white papers, and ebooks from industry thought leaders
  • Critical converage of the property casualty insurance and financial advisory markets on our other ALM sites, PropertyCasualty360 and ThinkAdvisor
NOT FOR REPRINT

© 2025 ALM Global, LLC, All Rights Reserved. Request academic re-use from www.copyright.com. All other uses, submit a request to [email protected]. For more information visit Asset & Logo Licensing.