This database was last updated in December 2015 ago and should only be used as a historical snapshot. More recent data on breaches affecting 500 or more people is available at the U.S. Department of Health and Human Services’ Breach Portal.

MARIN GENERAL HOSPITAL

250 BON AIR ROAD, PO BOX 8010 GREENBRAE,CA 94904

Cited by the California Department of Public Health for a violation of California’s Health and Safety Code relating to medical privacy during an inspection that began on January 10, 2013. Also cited in 63 other reports.


Report ID: 6LXT11, California Department of Public Health

Reported Entity: MARIN GENERAL HOSPITAL

Issue:

Based on interview and record review, the facility failed to prevent unauthorized access and disclosure of three patients' (Patient 1, Patient 2, and Patient 3) medical information when: A) Patient 1's medical information was faxed to a private individual instead of a pharmacy, and B) Patient 2's and Patient 3's medical information was faxed to two wrong physicians instead of the intended physicians. These failures allowed the unlawful or unauthorized access to protected health information.Findings:#1 CA00339010The California Department of Public Health was notified on 1/8/13 that a, "Breach of Protected Health Information (PHI)", occurred on 1/6/13.During an interview on 11/2/12 at 4 p.m., Administrative Staff A stated that, on 1/6/13, he was advised that a Private Individual had received Patient 1's PHI, which contained his name, sex, date of birth, allergies, age, acuity level, physician name, which was supposed to be faxed to the Outside Pharmacy only.Administrative Staff A further stated that it was human error, on the part of Licensed Staff B, in that she programmed the wrong fax number into the fax machine by transposing one number. The Outside Pharmacy fax number ended in #42 and the Private Individual's number ended in #82.#2 CA00339011The California Department of Public Health was notified on 1/8/13 that a, "Breach of Protected Health Information (PHI)", occurred on 1/3/13.During an interview on 1/22/13 at 10 a.m., Administrative Staff A stated that, on 1/3/13, that Unlicensed Staff C faxed laboratory results, which included name, sex, date of birth, medical record number, and physician's name for Patient 2, to Wrong Physician D instead of Patient 2's Physician as both physicians had similar last names but different first names. Administrative Staff A further stated that Unlicensed Staff C did not verify the first name of Patient 2's Physician before sending the fax.#3 CA00339020The California Department of Public Health was notified on 1/8/13 that a, "Breach of Protected Health Information (PHI)", occurred on 1/3/13.During an interview on 1/23/13 at 10:30 a.m., Administrative Staff A stated that, on 1/3/13, Licensed Staff E faxed laboratory results, which included Chemistry results, name, date of birth, physician's names, diagnosis, and medical record number for Patient 3, to Wrong Physician F instead of Patient 3's Physician as both physicians had the same last name but different first names. Administrative Staff A further stated that Licensed Staff E did not verify the first name of Patient 3's Physician before sending the fax.A review of the facility Policy and Procedure for, "CONFIDENTIALITY AND NON-DISCLOSURE AGREEMENT" (no date), reveals the following: "Obligations Regarding Confidentiality Patient health and facility organizational information is protected by law and by facility policies. The intent of these laws and policies is to assure that confidentiality of information is maintained while used for business and clinical operations."

Outcome:

Deficiency cited by the California Department of Public Health: Health & Safety Code 1280

Do you believe your privacy has been violated? Here’s what you can do: