This database was last updated in December 2015 ago and should only be used as a historical snapshot. More recent data on breaches affecting 500 or more people is available at the U.S. Department of Health and Human Services’ Breach Portal.

COMMUNITY REGIONAL MEDICAL CENTER

2823 FRESNO STREET FRESNO,CA 93715

Cited by the California Department of Public Health for a violation of California’s Health and Safety Code relating to medical privacy during an inspection that began on January 13, 2014. Also cited in 62 other reports.


Report ID: WHS611.01, California Department of Public Health

Reported Entity: COMMUNITY REGIONAL MEDICAL CENTER

Issue:

Based on staff interview, and administrative document review, the hospital failed to keep Protected Health Information (PHI) confidential when an employee inappropriately accessed nine patient's (Patients 1-9) medical records without a business need to know. These failures placed Patient 1-9's PHI at potential risk for unauthorized use.Findings:On 01/13/2014 at 3:40 p.m., during an interview the Privacy Officer (PO) stated on 12/11/2013 a Patient Care Assistant (PCA) accessed nine patient's medical records without a business need to know in order to monitor what other Patient Care Assistants were doing.Patient 1-9's PHI breached included name, date of birth, gender, medical record number, account number and clinical information.The Hospital's Policy and Procedure titled "HIPAA General Rules for the Use and Disclosure of PHI", dated 4/18/12, indicated "...It is the policy of [Hospital] to protect the privacy and security of patient information and to comply with the applicable laws and regulations. ...This policy applies to all [Hospital] workforce members, which includes employees...".

Outcome:

Deficiency cited by the California Department of Public Health: Patients' Rights

Related Reports:

Do you believe your privacy has been violated? Here’s what you can do: