Search Privacy Violations, Breaches and Complaints
This database was last updated in December 2015 ago and should only be used as a historical snapshot. More recent data on breaches affecting 500 or more people is available at the U.S. Department of Health and Human Services’ Breach Portal.
UNIVERSITY OF CALIFORNIA SAN FRANCISCO MEDICAL CENTER
Cited by the California Department of Public Health for a violation of California’s Health and Safety Code relating to medical privacy during an inspection that began on April 5, 2012. Also cited in 108 other reports.
Report ID: 1JNV11.01, California Department of Public Health
Reported Entity: UCSF MEDICAL CENTER
Issue:
Based on interview and record review, the facility failed to notify the California Department of Public Health (CDPH) of the breach of personal patient health information within the required five business days after the breach was detected.Findings:In an interview on 4/5/12 at 2:00 p.m., the Manager of Accreditation, Licensure and Certification (Staff A) stated that on 2/7/12 the facility learned that Patient 1's billing statement was sent to an incorrect address and opened by the person who received it. Staff A said Patient 1 was notified of the medical information breach by mail on 2/10/12. Staff A stated she did not think billing information was protected health information so she did not notify the CDPH until 2/28/12.A review of Patient 1's billing statement dated 2/8/12 indicated it contained the patient's name, medical record number and laboratory tests done.Review of the report to the CDPH notifying them of the medical information breach in indicated it was faxed on 2/28/12 at 3:56 p.m. The facility was 14 days late in reporting the information breach to the CDPH within five business days after it was detected.
Outcome:
Deficiency cited by the California Department of Public Health: Health & Safety Code 1280