This database was last updated in December 2015 ago and should only be used as a historical snapshot. More recent data on breaches affecting 500 or more people is available at the U.S. Department of Health and Human Services’ Breach Portal.

COMMUNITY REGIONAL MEDICAL CENTER

2823 FRESNO STREET FRESNO,CA 93715

Cited by the California Department of Public Health for a violation of California’s Health and Safety Code relating to medical privacy during an inspection that began on February 14, 2014. Also cited in 62 other reports.


Report ID: WLF011, California Department of Public Health

Reported Entity: COMMUNITY REGIONAL MEDICAL CENTER

Issue:

Based on staff interview, clinical record and administrative document review, the facility failed to keep Protected Health Information (PHI) confidential when:1. Patient 1's PHI was accessed and shared by an employee of a physician's office. This 2. Patient 2's PHI was accessed by an employee without authorization.3. Patient 3's PHI was accessed without by an employee of a physician's office. The employee's access to Epic ( computerized medical records and information) was terminated.4. Patient 4's financial statement was mailed to the wrong address. These failure placed Patient 1, 2, 3, and 4's PHI at risk for unauthorized use.Findings:Refer to CA003879501. On 4/18/14 at 10:30 a.m., during an interview, Staff 1 (Privacy Officer) stated on 2/6/14 at 08:56 Staff 2 accessed and shared Patient 1"s PHI without authorization.On 4/18/14 at 10:30 a.m., Patient 1's clinical record was reviewed. Patient 1's clinical record contained the following documentation: Name, date of birth, gender, address, social security number, medical record number, account number and clinical information related to Patient 1's 2/6/14 hospitalization. Refer to CA003889352. On 4/18/14 at 10:30 a.m., during an interview, Staff 1 stated that on 2/18/14 at 8:24 a.m., Staff 3 accessed Patient 2's PHI without authorization.On 4/18/14 at 10:30 a.m., Patient 2's clinical record was reviewed. Patient 2's clinical record contained the follwing documentation: Name, date of birth, gender, address, social security number, medical record number, account number, and clinical information.Refer to CA003892653. On 4/18/14 at 10:30 a.m., during an interview Staff 1 stated on 2/11/14 at 3:32 p.m., Staff 4 accessed Patient 3's PHI without authorization.On 4/18/14 at 10:30a.m., Patient 3's clinical record was reviewed. Patient 3's clinical record contained the following documentation: Name, date of birth, gender, address, social security number, medical record number, account number, and clinical information.Refer to CA00392558On 4/18/14 at 10:39 a.m., during and interview, the Privacy Officer stated on 3/19/14 Health Information Management office was notified by a private citizen for Patient 4's hospital bill in the mail. The private citizen was advised to destroy the financial statement. The Privacy Office stated Patient 4 could not be contated because Patient 4 was homeless.Review of Patient 4's financial statement indicated the statement contained name, address, account number, and amount owed.The facility policy and procedure titled "Confidentiality/Breach of Patient Information" indicated It is CMC's policy to protect the privacy and security of all patients, employee, and business information, and comply with State and Federal laws and regulations. CMC may only use or disclose PHI when the patient has given authorization unless information is used for disclosure for treatment , payment, healthcare operations or required by law."

Outcome:

Deficiency cited by the California Department of Public Health: Patients' Rights

Do you believe your privacy has been violated? Here’s what you can do: