Search Privacy Violations, Breaches and Complaints
This database was last updated in December 2015 ago and should only be used as a historical snapshot. More recent data on breaches affecting 500 or more people is available at the U.S. Department of Health and Human Services’ Breach Portal.
UNIVERSITY OF CALIFORNIA SAN FRANCISCO MEDICAL CENTER
Cited by the California Department of Public Health for violations of California’s Health and Safety Code relating to medical privacy during an inspection that began on August 21, 2014. Also cited in 108 other reports.
Report ID: 27M311.02, California Department of Public Health
Reported Entity: UCSF MEDICAL CENTER
Issue:
Based on interview and record review, the hospital failed to ensure confidentiality of Patients 2 and Patient 3's electronic medical records (EMR), when an employee (Temp 1) accessed these two records without authorization, and subsequently made harassing phone calls to Patient 2 using information from Patient 2's EMR, and may have tried to initiate a new credit card using information from Patient 3's EMR. Further investigation indicated Temp 1 accessed sixty-eight other patients' EMRs without business justification or authorization. This breach had the potential for embarrassment to the patients whose medical information was breached and for identity theft at a future date. Findings: Please see A017.
Outcome:
Deficiency cited by the California Department of Public Health: Patients' Rights