Search Privacy Violations, Breaches and Complaints
This database was last updated in December 2015 ago and should only be used as a historical snapshot. More recent data on breaches affecting 500 or more people is available at the U.S. Department of Health and Human Services’ Breach Portal.
MARIN GENERAL HOSPITAL
Cited by the California Department of Public Health for a violation of California’s Health and Safety Code relating to medical privacy during an inspection that began on November 6, 2013. Also cited in 63 other reports.
Report ID: VU3511.01, California Department of Public Health
Reported Entity: MARIN GENERAL HOSPITAL
Issue:
Based on interview and record review, the facility failed to prevent unauthorized access and disclosure of a patient's (Patient 1) protected health information, when some of Patient 1's medical information was faxed to the wrong party. This failure allowed the unlawful or unauthorized access to protected health information.Findings:The California Department of Public Health was notified on 10/4/13 that a, breach of protected health information occurred on 9/20/13.During an interview on 11/6/13 at 11 a.m., Administrative Staff A stated that he received notification from Management Staff C on 9/20/13, that she had been notified by Unlicensed Staff B that a copy of Patient 1's prescription for durable medical equipment had been faxed to Facility Organization D, in error. Patient 1's information included, name, date of birth, age, gender, account number, medical record number, physician's name, pain level, previous treatment, and an order for medical equipment. During an interview on 11/6/13 at 11 a.m., Administrative Staff A also stated that it was a human error, on the part of Unlicensed Staff B, in that she pressed the wrong preset fax number for Patient 1's Durable Medical Equipment Provider and Unlicensed Staff B realized her error and called Facility Organization D to notify them of the error and have the protected health information shredded. A review of the facility Policy and Procedure for, "CONFIDENTIALITY AND NON-DISCLOSURE AGREEMENT" (no date), reveals the following: "Obligations Regarding Confidentiality Patient health and facility organizational information is protected by law and by facility policies. The intent of these laws and policies is to assure that confidentiality of information is maintained while used for business and clinical operations."
Outcome:
Deficiency cited by the California Department of Public Health: Health & Safety Code 1280