This database was last updated in December 2015 ago and should only be used as a historical snapshot. More recent data on breaches affecting 500 or more people is available at the U.S. Department of Health and Human Services’ Breach Portal.

RIVERSIDE COUNTY REGIONAL MEDICAL CENTER

26520 CACTUS AVENUE MORENO VALLEY,CA 92555

Cited by the California Department of Public Health for a violation of California’s Health and Safety Code relating to medical privacy during an inspection that began on June 6, 2013. Also cited in 123 other reports.


Report ID: BCV511.01, California Department of Public Health

Reported Entity: RIVERSIDE COUNTY REGIONAL MEDICAL CENTER

Issue:

Based on interview and facility document review, the facility failed to prevent unauthorized access and/or disclosure of Patient 1 and Patient 2's medical information. A staff member copied portions of their medical record, and kept those copies unprotected. This failure had the potential to result in misuse of private/protected information.Findings:On June 6, 2013, at 3 p.m., the Privacy Officer (PO), was interviewed. The PO stated, Staff one was under investigation by Human Resources (HR) for an unrelated incident in January 2013. She stated about that same time Staff 1 was also on a leave of absence (LOA), and HR was unable to interview her. Upon her return on March 22, 2013, Staff 1 was able to be interviewed by HR. The PO stated, Staff 1 reached into her bag and pulled out the copied medical records of two former patients (Patient's 1 and 2). Staff one informed HR that she copied the medical record prior to her LOA two months earlier. At that point HR notified the PO to investigate the possible Breach. The PO stated she was able to substantiate the breach due to the copied records were either in Staff 1's possession while she was on LOA, or they were left in an unlocked mailbox at the nurses station that was accessible to all staff. In addition, the PO stated the medical record should never have been copied, as it was not necessary in order to perform staff 1's duties.A copy of the medical records that Staff 1 copied was reviewed. For Patient 1, the copies included lab results and prenatal records. These copies contained Patient 1's name, phone number, date of birth, laboratory results, and summary of previous pregnancies. For Patient 2 the "Interdisciplinary Patient Progress Notes," were copied and contained the name (Patient 1's name, Baby Boy), date of birth, medical record number, and information regarding Patient 1's lab results.The facility policy titled, "Patient Privacy, Confidentiality, Medical Records, and Access to, or Release or Disclosure of, Patient Information (revised January 2, 2009)" was reviewed. The policy indicated: "Purpose: To protect patients' right to privacy and security of their healthcare information......Personnel shall maintain the confidentiality/privacy of information contained in the medical records of patients and, except for the purposes of treatment, payment, or healthcare operations, shall not disclose patient information without the patient's written authorization......Medical Information: Any individually identifiable information, in electronic or physical form, in possession of or derived from a provider of health care, health care service plan, pharmaceutical company, or contractor regarding a patient's medical history, mental or physical condition, or treatment......Individually Identifiable Information: The medical information includes or contains any element of personal identifying information sufficient to allow identification of the individual, such as the patient's name...or other information that, alone or in combination with other publicly available information reveals the individual's identity..."

Outcome:

Deficiency cited by the California Department of Public Health: Health & Safety Code 1280

Related Reports:

Do you believe your privacy has been violated? Here’s what you can do: