This database was last updated in December 2015 ago and should only be used as a historical snapshot. More recent data on breaches affecting 500 or more people is available at the U.S. Department of Health and Human Services’ Breach Portal.

CONTRA COSTA REGIONAL MEDICAL CENTER

2500 ALHAMBRA AVE MARTINEZ,CA 94553

Cited by the California Department of Public Health for a violation of California’s Health and Safety Code relating to medical privacy during an inspection that began on February 13, 2013. Also cited in 103 other reports.


Report ID: APM311, California Department of Public Health

Reported Entity: CONTRA COSTA REGIONAL MEDICAL CENTER

Issue:

Based on interview and record review, the facility failed to prevent unauthorized access and disclosure of a patient's (Patient 1) medical information when her medical information was faxed to her employer. This failure allowed the unlawful or unauthorized access to Patient 1's medical information. Findings: The California Department of Public Health was notified on 2/11/13 that a, "Breach of Protected Health Information (PHI)", occurred on 1/17/13.During an interview on 2/21/13 at 10 a.m., Administrative Staff A stated that she was notified by Administrative Staff B, on 2/5/13, that Patient 1 called Unlicensed Staff D, on 2/5/13, and expressed concern that Patient 1's medical information, which included her diagnosis and treatment for a foot injury had been faxed to her employer.Administrative Staff A also stated that it was an error on the part of Licensed Staff C in that she failed to review the information prior to faxing, as Patient 1 had asked for the visit verification only, to be faxed, not any information relative to Patient 1's injury and the treatment thereof.A review of the facility Policy and Procedure for, "Confidentiality of Patient/Client Information", (6/11), reveals the following: "PURPOSE TO establish a department-wide policy that expresses the facilities commitment towards protecting a patient's right confidentiality...POLICY While individuals are patients/clients of the facilities, it is each employee's obligation to contribute to the provision of care in an environment that protects patient's/client's right to privacy. To accomplish this, all observations, and/or verbal, written, pictorial or photographic communications regarding patients/clients, in the absence of appropriate authority to access or release that information, should be safeguarded as 'CONFIDENTIAL'...RESPONSIBLE A. Employees 1. Each employee is responsible for keeping patient/client information confidential."

Outcome:

Deficiency cited by the California Department of Public Health: Health & Safety Code 1280

Do you believe your privacy has been violated? Here’s what you can do: