This database was last updated in December 2015 ago and should only be used as a historical snapshot. More recent data on breaches affecting 500 or more people is available at the U.S. Department of Health and Human Services’ Breach Portal.

COMMUNITY REGIONAL MEDICAL CENTER

2823 FRESNO STREET FRESNO,CA 93715

Cited by the California Department of Public Health for a violation of California’s Health and Safety Code relating to medical privacy during an inspection that began on March 21, 2014. Also cited in 62 other reports.


Report ID: XV7I11, California Department of Public Health

Reported Entity: COMMUNITY REGIONAL MEDICAL CENTER

Issue:

Based on staff interview, clinical and administrative document review, the facility failed to keep Protected Health Information (PHI) confidential when multiple staff members accessed Patient 1's (P 1) electronic medical records (EMR) without a business need to know.This failure resulted in unauthorized access to P 1's PHI and the potential for abuse of the PHI.Findings:On 3/21/14 at 1:47 p.m., the Privacy Officer (PO) stated it was brought to her attention by P 1's family, an excess number of visitors were presenting to P 1's room. The family was concerned because P 1 is a prominent member of the community, and an individual may have accessed and disclosed information to unauthorized individuals. This prompted an internal audit of the EMR of P 1. The internal audit indicated Registered Nurse (RN) 1, RN 2, RN 3, Certified Nursing Assistant (CNA), Medical Doctor (MD) 1, and MD 2 inappropriately accessed Patient 1's EMR. The PO stated these employees were not involved in the care of P 1, and had no need to access these records. The PHI breached included Patient 1's name, date of birth, address, gender, medical record number, account number, name of insurance, ancillary notes, progress notes, history and physical, flowsheets, problem list, imaging orders, cardiology consultation, medical history, home medications, and chief complaint.The (Hospital) Policy and Procedure titled, "HIPAA General Rules for the Use and Disclosure of PHI" dated 4/18/12 indicated, "The paper and electronic records...which contain PHI, are created and maintained for the purpose of providing patient care..."

Outcome:

Deficiency cited by the California Department of Public Health: Patients' Rights

Do you believe your privacy has been violated? Here’s what you can do: