Search Privacy Violations, Breaches and Complaints
This database was last updated in December 2015 ago and should only be used as a historical snapshot. More recent data on breaches affecting 500 or more people is available at the U.S. Department of Health and Human Services’ Breach Portal.
Mercy Medical Center
Cited by the California Department of Public Health for a violation of California’s Health and Safety Code relating to medical privacy during an inspection that began on October 31, 2014. Also cited in 34 other reports.
Report ID: FR8P11, California Department of Public Health
Reported Entity: MERCY MEDICAL CENTER
Issue:
Based on staff interview, clinical record and administrative document review, the facility failed to keep Protected Health Information (PHI) confidential when:1. Patient 1's medication reconciliation form (a facility form listing medications prescribed for the patient by a doctor) was included with Patient 2's transfer paperwork when Patient 2 left the facility. (CA00416068)2. Patient 3's medication reconciliation form (a facility form listing medications prescribed for the patient by a doctor) was included with Patient 4's transfer paperwork when Patient 4 left the facility. (CA00416364).These failures placed Patient 1 and Patient 3's PHI at a potential risk for unauthorized use.Findings:CA004160681. On 10/31/14 at 1:15 p.m., during an interview, the Health Information Portability and Accountability Act (HIPAA) Coordinator (HC) stated Patient 1's medication reconciliation form was included in Patient 2's transfer paperwork by the Registered Nurse (RN) 1. The HC stated RN 1 did not verify that the correct patient name appeared on all forms in the transfer paperwork. The HC stated RN 1 did not follow the hospital policy to verify the correct patient name is on all forms.The PHI disclosed included Patient 1's name, birth date, and medical record number.The facility policy and procedure titled, "HIPAA Sanctions for Breach of Patient Privacy or Confidentiality" dated 12/09, indicated "Policy:... Medical records... are "highly confidential" and must be protected from improper use and disclosure... III. Definitions: Breach of Patient Privacy or Confidentiality: Occurs when any [hospital] employee... B. Discloses (discusses or reveals) any individual's PHI for purposes not related to patient care and treatment..." CA004163642. On 10/31/14 at 1:24 p.m., the Health Information Portability and Accountability Act (HIPAA) Coordinator (HC) stated Patient 3's medication reconciliation form was included in Patient 4's transfer paperwork by the Registered Nurse (RN) 2. The HC stated RN 2 did not verify that the correct patient name appeared on all forms in the transfer paperwork. The HC stated RN 2 did not follow the hospital policy to verify the correct patient name is on all forms.The PHI disclosed included Patient 3's name, birth date, and medical record number.The facility policy and procedure titled, "HIPAA Sanctions for Breach of Patient Privacy or Confidentiality" dated 12/09, indicated "Policy:... Medical records... are "highly confidential" and must be protected from improper use and disclosure... III. Definitions: Breach of Patient Privacy or Confidentiality: Occurs when any [hospital] employee... B. Discloses (discusses or reveals) any individual's PHI for purposes not related to patient care and treatment..." .
Outcome:
Deficiency cited by the California Department of Public Health: Patients' Rights