Search Privacy Violations, Breaches and Complaints
This database was last updated in December 2015 ago and should only be used as a historical snapshot. More recent data on breaches affecting 500 or more people is available at the U.S. Department of Health and Human Services’ Breach Portal.
VA Sunshine Healthcare Network (VISN 8)
Mentioned in a privacy incident report created by the U.S. Department of Veterans Affairs on August 9, 2011. Also cited in 369 other reports.
Report ID: SPE000000065572, U.S. Department of Veterans Affairs
Reported Entity: VISN 08 Orlando, FL
Issue:
Four images of a patient's wound were posted to the a shared drive, in an unrestricted sub-directory titled "Scanned Images." The images contained the patient's name and date of birth. There were no full-face/full-body images. The images should have been posted to a department directory with limited access. This was discovered by a Quality Management Nurse who was examining the file for another purpose. The Privacy Officer is attempting to correlate the image dates with the patient's appointment history in an effort to pinpoint the employee who posted to the wrong file. Update: 08/09/11:The patient is deceased. The next of kin will be sent a Next Of Kin notification letter.
Outcome:
Staff is being reminded via newsletter to avoid posting PII to an unrestricted drive. This is also being briefed at Director's next Supervisor's Meeting.