This database was last updated in December 2015 ago and should only be used as a historical snapshot. More recent data on breaches affecting 500 or more people is available at the U.S. Department of Health and Human Services’ Breach Portal.

COMMUNITY REGIONAL MEDICAL CENTER

2823 FRESNO STREET FRESNO,CA 93715

Cited by the California Department of Public Health for a violation of California’s Health and Safety Code relating to medical privacy during an inspection that began on October 20, 2014. Also cited in 62 other reports.


Report ID: FW4C11, California Department of Public Health

Reported Entity: COMMUNITY REGIONAL MEDICAL CENTER

Issue:

Based on staff interview, clinical record, and administrative document review, the hospital failed to keep Protected Health Information (PHI) confidential when Patient 1's PHI was accessed on the hospital computer system and viewed without the business need to know. This failure resulted in the breach of Patient 1's PHI and the potential for unauthorized use. Findings: On 11/4/14 at 9 a.m., during an interview, the Privacy Officer (PO) stated Patient 1's PHI was breached on 10/6/14 when a medical doctor (MD) gained access to Patient 1's electronic clinical record on the hospital computer system by "Breaking the Glass". The definition of this term is accessing the electronic clinical record after warnings the record is not to be accessed by unauthorized staff for any reason. Review of the medical record indicated the following information was viewed by the MD in the electronic clinical record: Patients name, date of birth, date of service, medical record and account number, and clinical information related to Patient 1's hospitalization on 3/30/12.The hospital policy and procedure titled "HIPAA General Rules for the Use and Disclosure of PHI" dated 4/18/12, indicated "A. Protected Health Information and Records: 2. The paper and electronic records of ..., which contain PHI, are created and maintained for the purpose of providing patient care and for facilitating .... business processes. Any person who uses PHI and/or records from ... without authorization or for unauthorized purposes are subject to disciplinary action, ... B. ... Privacy and Policies Procedures: 2. It is the responsibility of all ... workforce members to comply with the policies and procedures and to cooperate with ... management to identify and correct problems that may cause privacy or security breaches. N. Data security: 1. Patients have the right to expect that their information is collected, stored and maintained in a reliable manner and sufficient precautions are taken by the ... to prevent its misuse."

Outcome:

Deficiency cited by the California Department of Public Health: Patients' Rights

Do you believe your privacy has been violated? Here’s what you can do: