Search Privacy Violations, Breaches and Complaints
This database was last updated in December 2015 ago and should only be used as a historical snapshot. More recent data on breaches affecting 500 or more people is available at the U.S. Department of Health and Human Services’ Breach Portal.
Northwest Network (VISN 20)
Mentioned in a privacy incident report created by the U.S. Department of Veterans Affairs on July 9, 2012. Also cited in 208 other reports.
Report ID: SPE000000077628, U.S. Department of Veterans Affairs
Reported Entity: VISN 20 Portland, OR
Issue:
Data collected on one VA Research subject screening form containing protected health information (PHI) was disclosed to a non-VA database for the study before authorization had been obtained from the subject to use or disclose his information. This disclosure occurred on 05/21/12 and was discovered when the study was being reviewed in late June 2012. The study protocol is overseen by the VA Central Institutional Review Board (IRB) but the mistake occurred at the Portland VAMC by researchers working with the local Principal Investigator (PI). The University maintaining the database has already deleted the form data entered for affected subject. Update: 07/09/12:Due to full SSN and medical information was disclosed, Patient A will be sent a letter offering credit protection services.
Outcome:
The data entered into the database was removed by the University.