This database was last updated in December 2015 ago and should only be used as a historical snapshot. More recent data on breaches affecting 500 or more people is available at the U.S. Department of Health and Human Services’ Breach Portal.

KAISER FOUNDATION HOSPITAL - FONTANA

9961 SIERRA AVE FONTANA,CA 92335

Cited by the California Department of Public Health for a violation of California’s Health and Safety Code relating to medical privacy during an inspection that began on August 9, 2013. Also cited in 6 other reports.


Report ID: 4CMF11.01, California Department of Public Health

Reported Entity: KAISER FOUNDATION HOSPITAL FONTANA

Issue:

Based on interview and record review, the facility failed to ensure the confidential treatment of protected health information (PHI) for Patient A, when a bill intended for Patient A was inadvertently sent to Patient B. This breach of Patient A's PHI placed the patient at risk for identity theft, and the unauthorized release of PHI to Patient B. FINDINGS:On February 12, 2013 1:35 PM, a phone interview was conducted with the facility privacy officer (FPO) to investigate an entity reported incident of a possible breach of PHI for Patient A.On August 9, 2013, a review was conducted of the entity reported incident. The Facility investigation was also reviewed which revealed that on October 30, 2012, Patient B informed and returned to the facility a letter of, "Co-Pay" which had been mailed to Patient B's address, with Patient A's name and PHI on it. Co-Pay letters are sent out to the patient by the Hospital Admitting Financial Counselors. Facility staff (Employees 1 and 2) failed to double check the address on the letter prior to it being mailed out. Patient A's PHI which was mailed to Patient B an unauthorized recipient, included the following: a "Reminder of Co-Payment Due" letter, which contained Patient A's name, medical record number, discharge date, and the balance due amount. On November 19, 2013 at 12:00 PM, a phone interview was conducted with the facility privacy officer, who confirmed the incident. She stated that the billing department had a letter template which they utilized for "Co Pay" billing. Apparently the employees (Employee 1 and 2) did not remove all the information from the previous billing which was sent out. Also, neither Employee 1 nor 2 cross checked the letter to ensure that the PHI was correct prior to mailing the billing, as is the practice in the facility. The Facility failed to protect patient rights regarding maintaining the privacy and confidentiality of patient (PHI), which resulted in Patient A being placed at risk of identity theft, when a bill containing Patient A's PHI was mailed to an unauthorized recipient.

Outcome:

Deficiency cited by the California Department of Public Health: Patients' Rights

Related Reports:

Do you believe your privacy has been violated? Here’s what you can do: