Search Privacy Violations, Breaches and Complaints
This database was last updated in December 2015 ago and should only be used as a historical snapshot. More recent data on breaches affecting 500 or more people is available at the U.S. Department of Health and Human Services’ Breach Portal.
UNIVERSITY OF CALIFORNIA SAN FRANCISCO MEDICAL CENTER
Cited by the California Department of Public Health for violations of California’s Health and Safety Code relating to medical privacy during an inspection that began on September 15, 2014. Also cited in 108 other reports.
Report ID: CYNO11.01, California Department of Public Health
Reported Entity: UCSF MEDICAL CENTER
Issue:
Based on interview and record review, the hospital failed to notify the California Department of Public Health regarding the breach of Patient 1's medical information until fifteen (15) days after detection.Findings:During an interview on 9/15/14 at approximately 10:00 AM, the hospital's Privacy Analyst (PA 1) stated that the Prepare Clinic faxed the results of Patient 1's urinalysis to a private residence instead of to Patient 1's primary physician. PA 1 stated that on 7/16/14, the occupant of the home where the fax was received, notified the Clinic that the fax had been received in error. PA 1 said the Clinic did not notify the Privacy Office in a timely manner so follow-up to the medical information breach was delayed.Record review indicated a faxed letter dated 7/31/14, notifying the California Department of Public Health (CDPH) of the medical information breach.Record review indicated a copy of a letter, dated 7/31/14, sent to Patient 1 notifying him/her of the breach of his/her medical information. This was eight (8) days after the five business day grace period for notification.The hospital was eight (8) days late in notifying CDPH of the breach of Patient 1's medical information.
Outcome:
Deficiency cited by the California Department of Public Health: Health & Safety Code 1280