Search Privacy Violations, Breaches and Complaints
This database was last updated in December 2015 ago and should only be used as a historical snapshot. More recent data on breaches affecting 500 or more people is available at the U.S. Department of Health and Human Services’ Breach Portal.
RIVERSIDE COUNTY REGIONAL MEDICAL CENTER
Cited by the California Department of Public Health for a violation of California’s Health and Safety Code relating to medical privacy during an inspection that began on May 27, 2014. Also cited in 123 other reports.
Report ID: FWM411, California Department of Public Health
Reported Entity: RIVERSIDE COUNTY REGIONAL MEDICAL CENTER
Issue:
Based on interview and record review, the facility failed to prevent the unauthorized access and/or disclosure of Patient A's private health information (PHI). A document containing Patient A's information was inadvertently mailed to an insurance company that was not Patient A's insurance provider. This had the potential to result in the misuse of Patient A's private health information.Findings:On May 27, 2014, at 2:34 p.m., an investigation was conducted on this entity reported incident. During a concurrent interview conducted with the facility Administrative Services Officer (ASO), the ASO stated on May 16, 2014, she was made aware of a facility breach of PHI in which an insurance company requested information on a Patient B. The billing department sent the requested information and and inadvertently included a letter concerning Patient A. The ASO stated, "The letter included Patient A's name, Medi-Cal policy number, and hospital account number." The ASO further stated,"The (insurance company's) Privacy Officer notified the hospital of the error on May 16, 2014."On May 27, 2014, a record review was conducted of the letter sent to Patient A, dated May 22, 2014. The letter indicated, "This disclosure occurred on May 6, 2014, when a letter with your information was inadvertently sent to an insurance company who is not your insurance carrier. The letter included your name, Medi-Cal policy number, your (hospital) account number. No other information about your healthcare was disclosed and none of your medical records have been affected."A review was conducted of the facility policy, dated August 27, 2013, titled, "Patient Privacy: (Health Insurance Portability and Accountability Act) or HIPPA. The policy indicated,"The policy of (hospital name withheld) provides guidance on the protection of patient privacy...2.2 Implement administrative, technical, and physical safeguards to prevent unauthorized or inappropriate access, use and/or disclosure of patient's protected health information."
Outcome:
Deficiency cited by the California Department of Public Health: Health & Safety Code 1280