This database was last updated in December 2015 ago and should only be used as a historical snapshot. More recent data on breaches affecting 500 or more people is available at the U.S. Department of Health and Human Services’ Breach Portal.

Mercy Medical Center


Cited by the California Department of Public Health for a violation of California’s Health and Safety Code relating to medical privacy during an inspection that began on March 6, 2015. Also cited in 34 other reports.

Report ID: W0BC11, California Department of Public Health



Based on staff interview, clinical record and administrative document review, the facility failed to keep Protected Health Information (PHI) confidential when more of Patient 1's clinical record was sent to a law office than was authorized by Patient 1.This failure placed Patient 1's PHI at a potential risk for unauthorized use.Findings:On 3/6/15 at 10:20 a.m., during an interview, the Privacy Officer (PO) stated Patient 1 authorized the facility to release three pages of her clinical record to a law office. The Document Services Technician 1 copied 37 pages of Patient 1's clinical record related to surgery and sent the copies to the law office. The PO stated the Document Services Technician did not check and verify what information was requested by the law office prior to sending the packet.The PHI disclosed included Patient 1's previous surgical history, diagnoses, medications, and lab results. The facility policy and procedure titled, "(HIPPA) Regulation, Release of Information in Accordance With State and Federal" dated 10/12, indicated, "1. Policy....It is the responsibility of the hospital to safeguard the integrity of content and the physical property of the patient chart, both paper and electronic, against loss, defacement, tampering or use by unauthorized individuals....".


Deficiency cited by the California Department of Public Health: Patients' Rights

Do you believe your privacy has been violated? Here’s what you can do: