Bringing transparency to federal inspections
Tag No.: A0147
Based on interview and record review, the facility failed to safeguard the personal health information (PHI) of Patient A. This resulted in two external agencies receiving Patient A's name, social security number, date of birth, telephone number and dates of service with diagnoses.
FindingsDuring the investigation of an entity self reported incident on 6/27/12, a review was done of the data that had been sent.
According to the Privacy Officer, "On 6/7/12, a case manager (CM) was trying to place a patient [Patient A] and transposed the fax numbers by reversing 8243 to 2843. The information contained Patient A's name, social security number, date of birth and dates with diagnoses of all visits.
A review of the letter sent to Patient A by the facility acknowledges the breach of his PHI.