Search Privacy Violations, Breaches and Complaints
This database was last updated in December 2015 ago and should only be used as a historical snapshot. More recent data on breaches affecting 500 or more people is available at the U.S. Department of Health and Human Services’ Breach Portal.
EISENHOWER MEDICAL CENTER
Cited by the California Department of Public Health for a violation of California’s Health and Safety Code relating to medical privacy during an inspection that began on July 24, 2014. Also cited in 279 other reports.
Report ID: V43H11.01, California Department of Public Health
Reported Entity: EISENHOWER MEDICAL CENTER
Issue:
Based on interview and record review, the facility failed to prevent unauthorized disclosure of PHI (protected health information) for one patient (Patient 1) when an employee faxed a neurology clinic visit summary to an incorrect fax number and it was received by a private business. This failed practice resulted in the potential for physical, emotional, and financial harm to Patient 1.Findings:During an interview with the facility Privacy Officer (PO) on July 24, 2014, at 2:25 p.m., the PO stated an employee from the neurology clinic was faxing a visit summary to the primary care physician for Patient 1, using the facility automated faxing system. The PO stated the physician's fax number had changed, but it had not been adjusted in the system. The PO stated when the employee selected the physician's name, she did not verify the fax number was correct, and the fax was received by a private business.A review of the documents faxed to the private business indicated they contained the following PHI for Patient 1:1. Name;2. Age;3. Date of birth;4. Sex;5. Location of the clinic she was seen in;6. Neurology clinic physician's name;7. Primary care physician's name;8. Fall history;9. Screening for depression;10. Screening for abuse;11. Brain CT (cat scan) results;12. Laboratory results;13. Patient's occupation;14. Husband's occupation;15. Medical record number:16. Cardiac history;17. Psychiatric history;18. Neurological history;19. Medical history;20. Surgical/medical procedure history;21. Medication list (including 26 medications);22. Family history;23. Information regarding siblings;24. Social history (smoking, drinking, religion, race, ethnicity, language);25. Physical examination;26. Diagnoses; and,27. Plan for further care.Failure of the employee to verify the documents were being sent to the correct fax number resulted in unauthorized persons having access to ten pages of PHI for Patient 1, and the potential for harm to her.
Outcome:
Deficiency cited by the California Department of Public Health: Health & Safety Code 1280