Search Privacy Violations, Breaches and Complaints
This database was last updated in December 2015 ago and should only be used as a historical snapshot. More recent data on breaches affecting 500 or more people is available at the U.S. Department of Health and Human Services’ Breach Portal.
COMMUNITY HOSPITAL OF SAN BERNARDINO
Cited by the California Department of Public Health for a violation of California’s Health and Safety Code relating to medical privacy during an inspection that began on June 26, 2012. Also cited in 46 other reports.
Report ID: I2UV11.01, California Department of Public Health
Reported Entity: COMMUNITY HOSPITAL OF SAN BERNARDINO
Issue:
Based on interview and record review, the facility failed to protect Patient A's protected health information (PHI) when her clinical record was sent to another patient. This had the potential to result in identity theft and was a breach of PHI.FindingsOn 6/26/12, an investigation was initiated into a possible breach of PHI for Patient A. A phone interview was conducted with the alternate privacy officer.During the interview the alternate privacy officer, she stated they used an outside company to copy their medical records when they are requested. The staff used a cover sheet which had the correct information on it for Patient A. When the staff went to copy the next chart, they had not changed from Patient A's information and inadvertently sent her clinical record to the wrong person.The PHI that was copied contained the patient's name, date of birth, phone number, social security number and dates of service with diagnoses.A review of the letter sent to Patient A confirmed that a breach had occurred.
Outcome:
Deficiency cited by the California Department of Public Health: PATIENT RIGHTS: CONFIDENTIALITY OF RECORDS