Search Privacy Violations, Breaches and Complaints
This database was last updated in December 2015 ago and should only be used as a historical snapshot. More recent data on breaches affecting 500 or more people is available at the U.S. Department of Health and Human Services’ Breach Portal.
RIVERSIDE COUNTY REGIONAL MEDICAL CENTER
Cited by the California Department of Public Health for a violation of California’s Health and Safety Code relating to medical privacy during an inspection that began on September 4, 2013. Also cited in 123 other reports.
Report ID: KY3P11.01, California Department of Public Health
Reported Entity: RIVERSIDE COUNTY REGIONAL MEDICAL CENTER
Issue:
Based on interview and record review, the facility failed to ensure protected health information (PHI) was kept protected, when written documentation provided to Patient B, contained Patient A's demographic information. This resulted in the unauthorized disclosure of Patient A's protected health information (PHI) to Patient B and the potential for misuse of the information.Findings:On September 4, 2013, at 1:45 p.m., an interview was conducted with the Compliance and Privacy Officer (CPO) and the Healthcare Administrative Surveyor (HAS). The CPO stated on August 16, 2013, Patient B was given an eligibility letter that contained Patient A's protected information. The CPO stated Patient B brought the document back to the business office on August 23, 2013. The CPO stated the document contained Patient A's full name, date of birth, address, medical record number and health plan beneficiary number. On September 4, 2013, a copy of Patient A's notification letter was reviewed. The letter indicated "on August 16, 2013...a copy of your Eligibility Letter...was inadvertently provided to another patient. The letter included your name, date of birth, health plan beneficiary number, medical record number and postal address." On September 4, 2013, a copy of the "Notice of MISP Eligibility Status," was reviewed. The Notice contained Patient A's address, identification number, date of birth, medical record number, copays and eligibility status. The facility policy and procedure titled "Breach of Patient Privacy: Reporting Requirements," dated September 23, 2009, revealed "... Breach: The unauthorized acquisition, access, use, or disclosure of patient protected health information (PHI) that compromises the security or privacy of the PHI...Medical information: any individually identifiable information, in electronic or physical form, in possession of or derived from a provider of health care, health care service..."
Outcome:
Deficiency cited by the California Department of Public Health: Health & Safety Code 1280