Search Privacy Violations, Breaches and Complaints
This database was last updated in December 2015 ago and should only be used as a historical snapshot. More recent data on breaches affecting 500 or more people is available at the U.S. Department of Health and Human Services’ Breach Portal.
COMMUNITY REGIONAL MEDICAL CENTER
Cited by the California Department of Public Health for a violation of California’s Health and Safety Code relating to medical privacy during an inspection that began on October 2, 2012. Also cited in 62 other reports.
Report ID: WRLP11, California Department of Public Health
Reported Entity: COMMUNITY REGIONAL MEDICAL CENTER
Issue:
Based on staff interview, clinical record and administrative document review, the hospital failed to protect patient confidential health information when Employee 1 accessed Patient 1's medical record without the need to know. This failure caused the breach of Patient 1's Protected Health Information (PHI) and possible unauthorized use. Findings:On 8/28/12 at 8:27 a.m., the department received a fax from the hospital that indicated an unauthorized access to patient medical information.On 10/2/12 at 11:19 a.m., during an interview, the Privacy Officer (PO) 1 indicated that Employee 1 accessed Patient 1's medical record without the need to know. PO 1 stated "Patient 1 received text message from Employee 1 that contained information she felt no one would have unless they looked at her medical record." PO stated, "I requested IT (information technology) audit and found out that Employee 1 accessed Patient 1's electronic medical record without legitimate reason to know." PO 1 indicated that the breached PHI contained Patient 1's name, date of birth, address, phone number, medical record number, and clinical information that related to Patient 1's admission to the hospital on 7/31/00. Patient 1's lab lab order was reviewed on 12/19/12. Patient 1's lab order contained name, date of birth, medical record number, account number, ordered tests, diagnoses, and family medical history.The hospital policy and procedure titled "Confidentiality/Breach of Information" dated 8/17/10, contained the following documentation: "A. Confidentiality of Patient Information: Protected health information is only to be accessed in relationship to an employee's or the health care provider's assigned job duties, on a business to know basis. Accessing any patient information ... without a business to know, without authorization, for unauthorized purposes, or not within your 'scope of assigned duties' is a breach of confidentiality. Access to protected health information is based on the business to know the information in order to perform yor assigned job duties."
Outcome:
Deficiency cited by the California Department of Public Health: Patients' Rights