This database was last updated in December 2015 ago and should only be used as a historical snapshot. More recent data on breaches affecting 500 or more people is available at the U.S. Department of Health and Human Services’ Breach Portal.

MARIN GENERAL HOSPITAL

250 BON AIR ROAD, PO BOX 8010 GREENBRAE,CA 94904

Cited by the California Department of Public Health for a violation of California’s Health and Safety Code relating to medical privacy during an inspection that began on August 15, 2013. Also cited in 63 other reports.


Report ID: NW6S11, California Department of Public Health

Reported Entity: MARIN GENERAL HOSPITAL

Issue:

Based on interview and record review, the facility failed to prevent unauthorized access and disclosure of sixteen patient's (Patient 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, and 16) medical information when a staff member's vehicle was broken into and Patient 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, and 16's protected health information was taken. This failure allowed the unlawful or unauthorized access to Patient 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, and 16's medical information. Findings:The California Department of Public Health was notified on 8/14/13 that a breach of protected health information occurred on 8/08/13.During an interview on 8/15/13 at 9:15 a.m., Administrative Staff A stated that he received a phone call on 8/09/13, from Licensed Supervisor C reporting that while visiting a friend in San Francisco, Licensed Staff B's car had been broken into and her purse containing clinical handwritten notes had been stolen on 8/8/13.During an interview on 8/15/13 at 9:15 a.m., Administrative Staff A also confirmed that thirteen letters were sent out on 8/14/13, to Patient 1, 3, 4, 5, 6, 8, 9, 10, 11, 12, 13, 14, and 15 advising them that a breach had occurred, on 8/08/13; and that three more were sent out, on 8/16/13, to Patients 2, 7, and 16 advising them of the breach. Their protected health information included: patient name, room number, medical record number, date of birth, gender, age, diagnoses, history, diet, body systems review, allergies, physician name, tests to be done, laboratory results, medications, and code status.During an interview on 8/15/13 at 9:15 a.m., Administrative Staff A further confirmed that there was no policy and procedure addressing clinical handwritten notes which included patients PHI and were not part of the original patient medical record being removed from the hospital's jurisdiction. Review of the facility Policy and Procedure for "Confidentiality Guidelines" (dated 5/13) reveals the following: "I. POLICY STATEMENT The confidentiality and security of medical, business, and personnel information is the responsibility of all hospital personnel...II. SPECIFIC PROCEDURAL INFORMATION..2.0 Medical Information...2.3.3 Removal of Records from the Hospital 2.3.3.1 The original patient medical record will not be removed from the hospital's jurisdiction and safekeeping except in accordance with a court order or subpoena".A review of the facility Policy and Procedure for, "CONFIDENTIALITY AND NON-DISCLOSURE AGREEMENT" (no date), reveals the following: "Obligations Regarding Confidentiality Patient health and facility organizational information is protected by law and by facility policies. The intent of these laws and policies is to assure that confidentiality of information is maintained while used for business and clinical operations."

Outcome:

Deficiency cited by the California Department of Public Health: Health & Safety Code 1280

Do you believe your privacy has been violated? Here’s what you can do: