Search Privacy Violations, Breaches and Complaints
This database was last updated in December 2015 ago and should only be used as a historical snapshot. More recent data on breaches affecting 500 or more people is available at the U.S. Department of Health and Human Services’ Breach Portal.
SUTTER COAST HOSPITAL
Cited by the California Department of Public Health for a violation of California’s Health and Safety Code relating to medical privacy during an inspection that began on August 28, 2014. Also cited in 58 other reports.
Report ID: OFPZ11.01, California Department of Public Health
Reported Entity: SUTTER COAST HOSPITAL
Issue:
Based on interview and document review, the facility failed to prevent unauthorized access and disclosure of Patient 50's confidential health information, when the patient's Physical Therapy Report was faxed to a private company, not involved with the patient's care and not authorized to have the information. This failure allowed for potential unlawful or unauthorized access to protected health information and a violation of the patient's right to privacy.Findings:During an interview on 8/28/14 at 10 a.m., the Privacy Officer stated that the incident occurred when an employee selected the wrong provider fax number from a list of programmed numbers. The Privacy Officer confirmed the information which was transmitted. Review of documents, provided by the facility, revealed the information which was misdirected included the patient's name, date of birth, medical record number, date of service and the initial Physical Therapy Report. This incident occurred due to human error when the employee mistakenly chose the wrong number from pre programmed numbers and did not verify that it was the correct number prior to transmitting the fax.
Outcome:
Deficiency cited by the California Department of Public Health: Health & Safety Code 1280