Accused EHR hacker sentenced to 30 months in prison
Photo: Ekaterina Bolotsova/Pexels
A Texas woman who was accused of stealing protected health information from a provider's electronic health record was sentenced this past week to 30 months in federal prison.
Amanda Lowry pleaded guilty this December to conspiracy to obtain information from a protected computer, said the Department of Justice in a press release.
"Today’s sentence is another example of the Eastern District’s commitment to vigorously defending protected health information and prosecuting those who exploit such information for their personal gain," said Acting U.S. Attorney Nicholas J. Ganjei in a statement.
WHY IT MATTERS
According to the agency, Lowry was accused of breaching an EHR in order to steal patients' PHI and personal data.
The stolen information was then repackaged in the form of fraudulent physician orders and then sold to durable medical equipment providers and contractors, says the DOJ.
Having obtained more than $1.4 million in proceeds, Lowry and her codefendants, Demetrius Cervantes and Lydia Henslee, allegedly used the money to buy SUVs, off-road vehicles and jet skis.
Cervantes was sentenced to four years in prison earlier this month; Henslee has not yet been sentenced.
THE LARGER TREND
Although healthcare breaches are becoming distressingly common, many of the high-profile hacks have been traced to shadowy groups, often overseas.
When individuals have been at fault, however, the consequences have been strict – in addition to prison time, people have faced firings and hefty fines for breaching private health information or snooping.
ON THE RECORD
"The defendant’s actions not only compromised victims’ sensitive information, exposing them to fraudulent schemes; but, also ultimately resulted in unnecessary costs to federal healthcare programs," said Ganjei.
Kat Jercich is senior editor of Healthcare IT News.
Twitter: @kjercich
Email: kjercich@himss.org
Healthcare IT News is a HIMSS Media publication.