Search Privacy Violations, Breaches and Complaints
This database was last updated in December 2015 ago and should only be used as a historical snapshot. More recent data on breaches affecting 500 or more people is available at the U.S. Department of Health and Human Services’ Breach Portal.
VA Mid South Healthcare Network (VISN 9)
Mentioned in a privacy incident report created by the U.S. Department of Veterans Affairs on August 9, 2011. Also cited in 328 other reports.
Report ID: SPE000000065566, U.S. Department of Veterans Affairs
Reported Entity: VISN 09 Nashville, TN
Issue:
A Veteran/employee requested from the Privacy Officer (PO), a Sensitive Access Report (SAR) to determine accesses to her record. Upon review of the SAR the Veteran/Employee noticed another employee within the same Service had accessed her CPRS records, twice on the same day back in 2010. The PO began an investigation and the employee could not justify access to this CPRS record to perform VA assigned duties. Update: 08/09/11:The Veteran/employee will be sent a letter offering credit protection services, due to full name and full SSN being accessed without authorization.
Outcome:
After PO investigation, it was confirmed one access to this record was considered inappropriate. CM Letter has been prepared and a redacted copy is attached. Privacy complaint letter was also sent to complainant. Disciplinary action was taken against the employee who could not justify access. Re-training was also required and completed.