Search Privacy Violations, Breaches and Complaints
This database was last updated in December 2015 ago and should only be used as a historical snapshot. More recent data on breaches affecting 500 or more people is available at the U.S. Department of Health and Human Services’ Breach Portal.
Northwest Network (VISN 20)
Mentioned in a privacy incident report created by the U.S. Department of Veterans Affairs on May 18, 2012. Also cited in 208 other reports.
Report ID: SPE000000075745, U.S. Department of Veterans Affairs
Reported Entity: VISN 20 Boise, ID
Issue:
A VA Employee/Veteran was arrested this week and it was in the local paper. The Privacy Officer (PO) ran a sensitive access report and will investigate why 8 staff had accessed the record this week. Will be questioning employees if PO cannot find a reason they were in the record. Update: 05/23/12: PO sent questioning email on Friday 05/18/12 to 8 staff members on why they accessed the record. Responses are due back by COB 05/25/12. Once the PO receives responses, PO will decide if violation occurred and will complete a report on the findings. 05/23/12: PO pulled another access list and found 2 more staff accessed the record since the original list was pulled. These additional 2 staff the PO could not find a reason for them to be in the record. PO has sent questioning emails to staff and also alerted the Supervisors. 05/30/12: Received 5 responses back from staff which were due on 05/25/12. The other staff the PO sent a reminder email and new due date of 05/31/12 to employee and Supervisor for responses back. 07/16/12: The veteran will receive a letter offering credit protection services
Outcome:
HR/Supervisors made aware of three violations and copies of findings. HR/Supervisor to determine potential further action against three employees. PO also requested the three employees retake the Privacy & HIPAA Training FY 12.