This database was last updated in December 2015 ago and should only be used as a historical snapshot. More recent data on breaches affecting 500 or more people is available at the U.S. Department of Health and Human Services’ Breach Portal.

CONTRA COSTA REGIONAL MEDICAL CENTER

2500 ALHAMBRA AVE MARTINEZ,CA 94553

Cited by the California Department of Public Health for a violation of California’s Health and Safety Code relating to medical privacy during an inspection that began on March 8, 2013. Also cited in 103 other reports.


Report ID: CPBQ11, California Department of Public Health

Reported Entity: CONTRA COSTA REGIONAL MEDICAL CENTER

Issue:

Based on interview and record review, the facility failed to prevent unauthorized access and disclosure of a patients' (Patient 1) medical information when Patient 1's PHI was handed to Patient 2. This failure allowed the unlawful or unauthorized access to Patient 1's medical information. Findings: The California Department of Public Health was notified on 3/6/13 that a, "Breach of Protected Health Information (PHI)", occurred on 1/30/13.During an interview on 3/8/13 at 10 a.m., Administrative Staff A stated that, she was notified by Administrative Staff B, on 2/28/13, that Unlicensed Staff C had called Administrative Staff B and notified her that Licensed Staff D had received information, on 3/27/13, from Patient 2's physician that Patient 2 had handed him, during her clinic appointment on 2/27/13, a diagnosis letter for Patient 1 (which the physician destroyed). Administrative Staff A stated that, Patient 1's PHI included her name, medical record number, home address, diagnosis, and physician name.Administrative Staff A further stated that it was an error, in not following policy and procedure, when Unlicensed Staff E handed Patient 2, on 1/30/13, the after visit summary, for Patient 1, without double checking Patient 2's identity.A review of the facility Policy and Procedure for, "Verifying the Identity and Authority of Individuals Requesting Use or Disclosure of Protected Health Information", (4/08), reveals the following: "POLICY The facility will take the necessary steps to verify the identity and legal authority of persons requesting a disclosure of protected health information...PROCEDURE 1... D. Disclosures to other requestors, including the patient/client/member. 1. If the requestor (individual or entity) is unknown, verify identity by requesting proof of identity, such as a photo ID, insurance card, business card, driver's license, or compare signatures recorded in the health records, etc., as reasonable and appropriate under the circumstances". A review of the facility Policy and Procedure for, "PATIENT IDENTIFICATION PROCESS", (9/11), reveals the following: "III POLICY Ambulatory Care staff at all facility health centers will will protect and accurately identify each patient that we serve. Staff must reliably identify the individual as the person for whom the service or treatment is intended, must match the service or treatment to that individual, and must secure their protected health information and medical record accuracy at all encounters...V PROCEDURE F. Clinical and ancillary services staff will be responsible for verifying the patients' identity prior to rendering care, performing diagnostic studies, giving medications and treatments".

Outcome:

Deficiency cited by the California Department of Public Health: Health & Safety Code 1280

Do you believe your privacy has been violated? Here’s what you can do: