A Yonkers hospital to pay $80K for allegedly leaking COVID-19 patient data

The U.S. Department of Health and Human Services Office for Civil Rights announced it has settled with the Saint Joseph’s Medical Center in Yonkers, New York, related to a charge of unlawful release of early COVID-19 patients’ protected health information to a national media outlet on April 20, 2020.

WHY IT MATTERS

According to a statement Monday, HHS said that it began investigating the hospital for a potential breach of the Health Insurance Portability and Accountability Act of 1996 Privacy Rule related to the inclusion of three COVID-19 patients’ protected health information in Associated Press news.

In the resolution agreement, HHS said OCR began investigating Saint Joseph’s Medical Center “after the Associated Press published an article about the medical center’s response to the COVID-19 public health emergency, which included photographs and information about the facility’s patients” on April 28, 2020. 

OCR said sharing the patient images and information, distributed nationally through the news, violated national patient-privacy-protection law. The PHI exposed included patient COVID-19 diagnoses, current medical statuses and medical prognoses, vital signs and their treatment plans, according to the press announcement.

“When receiving medical care in hospitals and emergency rooms, patients should not have to worry that providers may disclose their health information to the media without their authorization,” said OCR Director Melanie Fontes Rainer in the statement. 

Regulated entities cannot disclose PHI to the media – pandemic or not – without first obtaining written authorization from the patient permitting the entity to do so. 

“This includes when healthcare providers have print or television reporters on the premises,” HHS noted.

Saint Joseph’s Medical Center must pay $80,000 to OCR and implement a corrective action plan requiring the facility “to develop written policies and procedures that comply with the HIPAA Privacy Rule.” 

The medical center also agreed to train its workforce on the revised policies and procedures under the agreement with the federal agency. OCR said it would monitor St. Joseph’s for two years to ensure its compliance.

THE LARGER TREND

OCR settlements with healthcare providers, healthcare technology vendors and others can cost a health system millions of dollars for breaches of PHI, and for right of access investigations, which began in 2019.

In 2020, OCR fined CHSPSC, a Tennessee-based management company that provides IT and services to providers that is indirectly owned by Community Health Systems, $2.3 million for a 2014 cyber breach. Over four months, cybercriminals exfiltrated the PHI of more than six million people across 237 covered entities in the publicly traded health system from CHSPSC’s servers.

Health system culpability for HIPAA violations has significantly increased along with growing cybersecurity threats since the law was signed in 1996 and more recently with information blocking requirements under the 20th Century Cures Act.

Exceptions to info blocking are being finalized by HHS, but they require special attention from providers, according to legal experts, which is adding to healthcare’s administrative burden.

Beyond monetary civil penalties, criminal penalties can also be imposed for intentional violations of HIPAA – such as when employees snoop on electronic health records or when they share patient information with media during the height of pandemic hysteria. Only certain disclosures without patient consent are authorized for public health purposes under the guidance OCR issued in December 2020, such as sharing COVID-19 diagnoses with health information exchanges.

ON THE RECORD

“Providers must be vigilant about patient privacy and take necessary steps to protect it and follow the law,” Fontes Rainer said in a statement.

“The Office for Civil Rights will continue to take enforcement actions that put patient privacy first.”

Andrea Fox is senior editor of Healthcare IT News.
Email: afox@himss.org

Healthcare IT News is a HIMSS Media publication.

Note: This article have been indexed to our site. We do not claim legitimacy, ownership or copyright of any of the content above. To see the article at original source Click Here

Related Posts
동계올림픽 개막식에 ‘한복 차림’ 여성?…이재명은 “문화공정 반대” thumbnail

동계올림픽 개막식에 ‘한복 차림’ 여성?…이재명은 “문화공정 반대”

배현진 국민의힘 의원은 SNS에서 박병석·황희 겨냥 4일 생중계된 ‘2022 베이징 동계올림픽’ 개막식에 한복으로 보이는 옷차림의 소수민족 대표(왼쪽 노란 동그라미)가 등장해 온라인상에서 논란이 일고 있다. KBS 유튜브 영상 캡처 4일 생중계된 ‘2022 베이징 동계올림픽’ 개막식에 한복으로 보이는 옷차림의 소수민족 대표가 등장해 온라인상에서 논란이 일고 있다. 개막식 영상을 본 대다수 누리꾼들은 ‘한복을 입고서 당당히 있다’며 분노했고, 정치권…
Read More
Rashmika Mandanna's love for jhumkas thumbnail

Rashmika Mandanna’s love for jhumkas

Rashmika Mandanna, one of most cutest actresses, has charmed the audience not only with her acting skills but also with her impeccable fashion sense.Her love for jhumkas has become a prominent style statement. The actress not only flaunts jhumkas but has also given it a modern twist with every putfit. Her collection of this traditional jewellery
Read More

Resumo quinzenal do Portal PEBMED: Infecção alcóolica, atopia, Covid-19 e muito mais

Avalie o nosso conteúdo: Houve um erro fazendo sua requisição, por favor tente novamente! Obrigado!Sua avaliação é fundamental para que a gente continue melhorando o Portal Pebmed O Portal PEBMED é destinado para médicos e demais profissionais de saúde. Nossos conteúdos informam panoramas recentes da medicina. Caso tenha interesse em divulgar seu currículo na internet,…
Read More
Index Of News
Total
0
Share