Privacy in the spotlight 2010

21

Transcript of Privacy in the spotlight 2010

Page 1: Privacy in the spotlight 2010
Page 2: Privacy in the spotlight 2010

OCR stepping up HIPAA privacy, security enforcement

Page 3: Privacy in the spotlight 2010
Page 4: Privacy in the spotlight 2010
Page 5: Privacy in the spotlight 2010
Page 6: Privacy in the spotlight 2010

Criminal Penalties

• When an individual or covered entity knowingly violates HIPAA and discloses a patient's private health information, they can face up to $50,000 in fines and up to one year in prison.

• When the offense is committed under false pretenses, the penalties are higher. Up to $100,000 in fines can be assessed, and violators can spend up to five years in prison.

Page 7: Privacy in the spotlight 2010

Privacy violation: Patient records improperly disposed of

•Rite Aid Agrees to Pay $1 Million to Settle HIPAA Privacy Case

•CVS to pay $2.25 million to settle HIPAA violation

Page 8: Privacy in the spotlight 2010

Where did the data end up: In a public dump

What information was revealed: Names, addresses, dates of birth, Social Security numbers, insurance information (including policy numbers), patient identification numbers, as well as protected health information such as diagnoses relating to pathology tests

Page 9: Privacy in the spotlight 2010

Privacy violation:Patient information faxed to a business

Page 10: Privacy in the spotlight 2010

Where did the data end up: An auto shopWhat information was revealed: Six patients' names, dates of birth, and details about the visits

What makes this case special: Unlike so many other examples, this breach of patient confidentiality was accidental. A test fax should have been sent first.

Page 11: Privacy in the spotlight 2010

Privacy violation: The selling of patient information

Page 12: Privacy in the spotlight 2010

Where did the data end up: A recycling centerWhat information was revealed: Names of patients, as well as their addresses, phone numbers and medical record numbers all on printoutsWho was responsible: Hospital janitor Robert SandersWhat makes this case special: Sanders sold 30,000 patient record printouts for $40

Page 13: Privacy in the spotlight 2010

Privacy violation:Patient information reproduced, posted

publicly

Page 14: Privacy in the spotlight 2010

Who was responsible: Five nurses

What makes this case special: While no patient names, photographs or identifying information appear to have been used, according to the hospital, management insisted on pursuing termination hearings for the employees involved.

Where did the data end up:

Page 15: Privacy in the spotlight 2010

Privacy violation: Personal discussions involving patients

Page 16: Privacy in the spotlight 2010

Where did the data end up:Facebook and in cell phone photos

What went down: Pictures were taken of an X-ray

Who was involved: Two nurses employed by Mercy Walworth

Response: The nurses were fired.

Page 17: Privacy in the spotlight 2010
Page 18: Privacy in the spotlight 2010

Instead of treating a 60-year-old stabbing victim after his initial arrival at St. Mary Medical Center's ER, nurses and other staff took photos of the man and posted them on Facebook, the Los Angeles Times reports.

Page 19: Privacy in the spotlight 2010
Page 20: Privacy in the spotlight 2010

Oakwood Hospital Employee Fired for Facebook Posting”

“Nurses' jobs at risk for allegedly posting patient info on Facebook”

“Hospital worker fired over Facebook comments”

“Single tweet by hospital employee to Mississippi governor violates HIPAA and gets her fired”

“Nurses Fired Over Cell Phone Photos Of Patient”

Page 21: Privacy in the spotlight 2010

Captured on Facebook, the food-fighting nurses at hospital where

1,200 died.