HIPAA Helper »
SUTTER COAST HOSPITAL »
Aug 28, 2014

This database was last updated in December 2015 ago and should only be used as a historical snapshot. More recent data on breaches affecting 500 or more people is available at the U.S. Department of Health and Human Services’ Breach Portal.

SUTTER COAST HOSPITAL

800 E WASHINGTON BLVD CRESCENT CITY,CA 95531

Cited by the California Department of Public Health for a violation of California’s Health and Safety Code relating to medical privacy during an inspection that began on August 28, 2014. Also cited in 58 other reports.


Report ID: ZMVG11.01, California Department of Public Health

Reported Entity: SUTTER COAST HOSPITAL

Issue:

Based on interview and document review, the facility failed to prevent unauthorized access and disclosure of Patient 41's confidential health information, when results of laboratory tests were misdirected and given to a person not involved with the patient's care and not authorized to have the information. This failure allowed for potential unlawful or unauthorized access to protected health information and a violation of the patient's right to privacy.Findings:During an interview on 8/28/14 at 10 a.m., the Privacy Officer stated that the incident occurred when results of a laboratory test were to be provided to a physician. The employee sending the information did not have the physician's first name and was given a name which she then selected from the list and sent the results to that office. The physician had changed his location and the office forwarded the documents to his current location. Coincidentally, there was an employee at the new location with the name that the facility had identified in the address on the documents (not the correct first name) and the documents were given to an employee in the Purchasing Department at the second destination rather than the intended physician. The Privacy Officer confirmed the information which was transmitted. Review of documents, provided by the facility, revealed the information which was contained in the documents included the patient's name, date of birth, contact phone number, medical record and account numbers and the results of the tests which had been performed.This incident occurred due to the failure of the employee to confirm the full name and contact location prior to sending the documents to an outside agency or person.

Outcome:

Deficiency cited by the California Department of Public Health: Health & Safety Code 1280

Related Reports:

Do you believe your privacy has been violated? Here’s what you can do: