Search Privacy Violations, Breaches and Complaints
This database was last updated in December 2015 ago and should only be used as a historical snapshot. More recent data on breaches affecting 500 or more people is available at the U.S. Department of Health and Human Services’ Breach Portal.
SUTTER COAST HOSPITAL
Cited by the California Department of Public Health for a violation of California’s Health and Safety Code relating to medical privacy during an inspection that began on July 30, 2013. Also cited in 58 other reports.
Report ID: IOYP11.01, California Department of Public Health
Reported Entity: SUTTER COAST HOSPITAL
Issue:
Based on interview and record review, the facility failed to prevent unauthorized disclosure of Patient 7's protected, confidential health information, when Patient 7's private information was faxed to a facility not involved with the patient's care and not authorized to receive the information. This failure allowed for potential unlawful or unauthorized use of the information and was a violation of the patient's right to privacy. Findings: During an interview on 7/30/13 at 1:30 p.m., the Compliance Officer confirmed that the patient's private information had been sent to an outside facility in error. The fax number which was dialed was incorrect. The employee recognized the error and thought that she had canceled the fax, but had misinterpreted the required response and the fax was not canceled. The Compliance Officer confirmed the information which was shared. The information which was shared included the patient's name, date of birth, account and insurance numbers, address, phone number, responsible party, illness and medical information. The incident resulted from the employee's failure to verify the fax number prior to transferring the document.
Outcome:
Deficiency cited by the California Department of Public Health: Health & Safety Code 1280