This database was last updated in December 2015 ago and should only be used as a historical snapshot. More recent data on breaches affecting 500 or more people is available at the U.S. Department of Health and Human Services’ Breach Portal.

CONTRA COSTA REGIONAL MEDICAL CENTER

2500 ALHAMBRA AVE MARTINEZ,CA 94553

Cited by the California Department of Public Health for a violation of California’s Health and Safety Code relating to medical privacy during an inspection that began on September 4, 2013. Also cited in 103 other reports.


Report ID: I0KJ11, California Department of Public Health

Reported Entity: CONTRA COSTA REGIONAL MEDICAL CENTER

Issue:

Based on interview and record review, the facility failed to prevent unauthorized access and disclosure of two patients' (Patient 1 and Patient 3) medical information when Patient 1's printed wristband was placed on Patient 2's wrist and Patient 3's printed wristband was placed on Patient 4's wrist This failure allowed the unlawful or unauthorized access to some of Patient 1 and Patient 2's medical information. Findings: CA00368010 The California Department of Public Health was notified on 8/29/13 that a, "Breach of Protected Health Information (PHI)", occurred on 8/27/13.During an interview on 9/4/13 at 2 p.m., Administrative Staff A stated that, on 8/27/13, she was notified by Administrative Staff D that Patient 1's printed wristband was placed on Patient 2's wrist, on 8/27/13, by Licensed Staff B.Administrative Staff A also stated that the breach had been discovered, on 8/27/13, by Licensed Staff C. Patient 1's PHI included Patient 1's name, hospital record number,medical record number, gender, admission date, and type of admission.Administrative Staff A further stated that it was an error, in not following policy and procedure, when Licensed Staff B placed Patient 1's wristband on Patient 2's wrist, without double checking Patient 2's identity using two identifiers.Findings: CA00368025The California Department of Public Health was notified on 8/29/13 that a, "Breach of Protected Health Information (PHI)", occurred on 8/27/13.During an interview on 9/4/13 at 2:45 p.m., Administrative Staff A stated that, on 8/27/13, she was notified, by the Safety and Event Reporting System, that Patient 3's printed wristband was placed on Patient 4's wrist and that Patient 4's printed wristband was placed on Patient 3's wrist, on 8/27/13, by Unlicensed Staff E.Administrative Staff A also stated that the breach had been discovered, on 8/27/13, by Unlicensed Staff E shortly thereafter. Patient 3 and Patient 4's PHI included patient's name, hospital record number, medical record number, gender, admission date, and type of admission.Administrative Staff A further stated that it was an error, in not following policy and procedure, when Unlicensed Staff E placed the wristbands on each patient's wrist, without double checking their identity using two identifiers.A review of the facility Policy and Procedure for, "PATIENT IDENTIFICATION PROCESS", (9/11), reveals the following: "III POLICY Ambulatory Care staff at all facility health centers will will protect and accurately identify each patient that we serve. Staff must reliably identify the individual as the person for whom the service or treatment is intended, must match the service or treatment to that individual, and must secure their protected health information and medical record accuracy at all encounters...V PROCEDURE F. Clinical and ancillary services staff will be responsible for verifying the patients' identity prior to rendering care, performing diagnostic studies, giving medications and treatments".

Outcome:

Deficiency cited by the California Department of Public Health: Health & Safety Code 1280

Do you believe your privacy has been violated? Here’s what you can do: