This database was last updated in December 2015 ago and should only be used as a historical snapshot. More recent data on breaches affecting 500 or more people is available at the U.S. Department of Health and Human Services’ Breach Portal.

ST MARY MEDICAL CENTER

18300 HIGHWAY 18 APPLE VALLEY,CA 92307

Cited by the California Department of Public Health for a violation of California’s Health and Safety Code relating to medical privacy during an inspection that began on April 2, 2015. Also cited in 55 other reports.


Report ID: R7Q111, California Department of Public Health

Reported Entity: ST MARY MEDICAL CENTER

Issue:

Based on interview and record review, the facility failed to ensure the confidential treatment of protected health information (PHI) for four patients (Patients A,B,C,and D) when their medical information was inadvertently faxed to the external chart auditor company, instead of the internal health plan. This resulted in the unauthorized release of PHI for Patients A,B,C,and D.Findings:During a phone interview on April 3, 2015 at 11:50 AM, with the Risk Coordinator (RC) to investigate an entity reported incident of a breach of protected health information for Patients A,B,C,and D, she stated, the Authorization Coordinator (AC) failed to verify fax numbers before sending documents, and was counseled for breach of Patients A,B,C, and D's PHI. Patients A,B,C, and D were notified of the breach of their PHI by certified mail.During a phone interview on April 10, 2015 at 9:55 AM, with the AC she stated, she was faxing documents to a health plan but she pressed number 888 instead of 866 and the documents went to the external chart auditor company instead of the health plan. When asked how to prevent a reoccurrence of faxing documents to the wrong facility, she stated she will triple check everything: documents and fax number, before faxing the documents to facilities.During a review of the PHI breached for each patient the following was found:a. Patient A's name, date of birth, gender, medical record number, admission date, discharge date, attending physician, admitting diagnosis, religion, and home phone number.b. Patient B's name, date of birth, gender, admission date, discharge date, attending physician, diagnosis, medical record number, emergency contact, home phone numbers, consulting physician, and allergies.c. Patient C's name, date of birth, gender, admission date, discharge date, diagnosis, medical record number, emergency contact, work number, medications, laboratory results, progress notes, physician, vital signs, and echocardiogram report (A test that can evaluate the structures of the heart). d. Patient D's date of birth, gender, admission date, discharge date, physician, diagnosis, medical record number, mental status, race, religion, home phone number, work phone number, emergency contact, health insurance, allergies, and medications.

Outcome:

Deficiency cited by the California Department of Public Health: Patients' Rights

Do you believe your privacy has been violated? Here’s what you can do: