Search Privacy Violations, Breaches and Complaints
This database was last updated in December 2015 ago and should only be used as a historical snapshot. More recent data on breaches affecting 500 or more people is available at the U.S. Department of Health and Human Services’ Breach Portal.
Northwest Network (VISN 20)
Mentioned in a privacy incident report created by the U.S. Department of Veterans Affairs on March 2, 2012. Also cited in 208 other reports.
Report ID: SPE000000072414, U.S. Department of Veterans Affairs
Reported Entity: VISN 20 White City, OR
Issue:
A former employee requested "a list of all persons who accessed her computer medical records from 01/01/95 to 02/03/12." The Privacy Officer (PO) reviewed the Sensitive Patient Access Report (SPAR) and identified her ex-husband who is a current employee had accessed her account on 02/01/12 without authorization. Both personally identifiable information (PII) and protected health information (PHI) were compromised. Update: 03/02/12:The former employee will receive a letter offering credit protection services.
Outcome:
On February 22 the employees supervisor was notified of the unauthorized electronic access. On March 1 the supervisor counseled the employee on the inappropriateness of his behavior and notified him of the intent to pursue disciplinary action. An appointment has been set with Human Resources to draft this action. On March 5 the letter offering credit monitoring was sent to the former employee via mail.