This database was last updated in December 2015 ago and should only be used as a historical snapshot. More recent data on breaches affecting 500 or more people is available at the U.S. Department of Health and Human Services’ Breach Portal.

RIVERSIDE COUNTY REGIONAL MEDICAL CENTER

26520 CACTUS AVENUE MORENO VALLEY,CA 92555

Cited by the California Department of Public Health for a violation of California’s Health and Safety Code relating to medical privacy during an inspection that began on September 4, 2013. Also cited in 123 other reports.


Report ID: L4MT11.01, California Department of Public Health

Reported Entity: RIVERSIDE COUNTY REGIONAL MEDICAL CENTER

Issue:

Based on interview and record review, the facility failed to ensure protected health information (PHI) was kept protected, when the wrong name was placed on Patient B's written prescription. This resulted in the unauthorized disclosure of Patient A's protected health information (PHI) to Patient B and the potential for misuse of the information.Findings:On September 4, 2013, at 1:45 p.m., an interview was conducted with the Compliance and Privacy Officer (CPO) and the Healthcare Administrative Surveyor (HAS). The CPO stated Patient B was given a prescription on August 14, 2013. The CPO stated the prescription contained medications that were ordered for Patient B, but the prescription contained the wrong patient's name. The CPO stated the physician's assistant entered the wrong patient name on the prescription. On September 4, 2013, a copy of Patient A's notification letter was reviewed. The letter indicated "on August 15, 2013...demographic information was inadvertently placed on another patient's prescription. The Demographic information included you full name, and the date of your visit to the Emergency Room."On September 4, 2013, a copy of the "ED Prescription Sheet-Patient Copy," was reviewed. The prescription contained Patient A's name and the date of the Emergency Room visit. The facility policy and procedure titled "Breach of Patient Privacy: Reporting Requirements," dated September 23, 2009, revealed "... Breach: The unauthorized acquisition, access, use, or disclosure of patient protected health information (PHI) that compromises the security or privacy of the PHI...Medical information: any individually identifiable information, in electronic or physical form, in possession of or derived from a provider of health care, health care service..."The facility policy and procedure titled "Patient Identification," with a release date of May 23, 2012, revealed "This Policy and Procedure establishes a standard process to verify patient identity using two unique identifiers, when providing care, treatment, and services." According to the policy, "all healthcare team members will use two unique, patient-specific identifiers...patient full name...patient date of birth..."

Outcome:

Deficiency cited by the California Department of Public Health: Health & Safety Code 1280

Related Reports:

Do you believe your privacy has been violated? Here’s what you can do: