F0583 F583: Keep residents' personal and medical records private and confidential.
D

Violation of Resident's Right to Confidentiality

Waters Of Lebanon, TheLebanon, Indiana Survey Completed on 03-07-2024

Summary

The facility failed to ensure a resident's right to have his medical record kept private and confidential. The Business Office Manager (BOM) disclosed clinical information about Resident H's medical condition, treatment, and services to the resident's family without the resident's permission. This information was shared during a private meeting outside of the facility property. The BOM, who is not authorized to provide clinical information, shared details such as the lack of wound care and physical therapy notes, her opinion on the resident's mental capacity, and overheard conversations between a facility nurse and the resident's dialysis center. The Regional Nurse Consultant (RNC) and the Director of Nursing (DON) confirmed that the BOM's actions were outside her scope of practice and constituted a HIPAA violation, as the resident did not have a Power of Attorney (POA) and was listed as his own responsible party with normal cognitive function. Resident H, a long-term care resident with diagnoses including End Stage Renal Disease, Type 2 Diabetes, and Diabetic Neuropathy, was cognitively intact with a Brief Interview for Mental Status (BIMS) score of 15 out of 15. The facility's guidelines on resident rights and HIPAA privacy were not followed, as the BOM improperly shared confidential health information without the resident's consent. The facility's policies clearly state that only clinical staff are permitted to provide clinical information to residents or their POA, and any unauthorized sharing of health information is considered a violation of HIPAA regulations.

Penalty

No penalty information released
tooltip icon
The penalty, as released by CMS, applies to the entire inspection this citation is part of, covering all citations and f-tags issued, not just this specific f-tag. For the complete original report, please refer to the 'Details' section.

Resources

Below are regulatory guidelines relevant to this citation:

See other F0583 citations in Ohio
Failure to Ensure Privacy During Incontinence Care
D
F0583 F583: Keep residents' personal and medical records private and confidential.
Short Summary

A cognitively intact, fully dependent and always incontinent resident received incontinence care from a CNA in a shared room without the privacy curtain being drawn, despite the roommate being present. During the care, the resident’s genital area and buttocks were exposed while the CNA removed the adult brief and cleaned the resident. The resident later reported that staff sometimes forget to pull the curtain and that this exposure sometimes bothers him, and the CNA acknowledged not using the privacy curtain, contrary to facility policy on resident privacy during personal care.

No penalty information released
tooltip icon
The penalty, as released by CMS, applies to the entire inspection this citation is part of, covering all citations and f-tags issued, not just this specific f-tag. For the complete original report, please refer to the 'Details' section.
Unauthorized Cellphone Recording of Resident Without Consent
D
F0583 F583: Keep residents' personal and medical records private and confidential.
Short Summary

A cognitively intact resident with Huntington’s disease and other conditions was participating in chair exercises when a CNA used a personal cellphone to record the resident lifting her leg above her head, without any signed photo release or consent from the resident’s POA. Two other CNAs watched the event and did not report it. Other staff later observed the CNAs laughing and viewing the image on the phone. Review of incident reports, staff statements, and the facility’s social media policy confirmed that the recording was taken in the work area using a personal device and that facility policy prohibits taking or sharing resident photos or videos without prior written permission.

No penalty information released
tooltip icon
The penalty, as released by CMS, applies to the entire inspection this citation is part of, covering all citations and f-tags issued, not just this specific f-tag. For the complete original report, please refer to the 'Details' section.
Privacy Breach When Wrong Discharge Medications and Instructions Given to Another Resident
D
F0583 F583: Keep residents' personal and medical records private and confidential.
Short Summary

A resident who was cognitively intact and required supervision with ADLs was discharged, and an LPN mistakenly sent that resident’s representative home with another resident’s medications and written discharge instructions, which included detailed information on multiple prescribed drugs for serious conditions such as cerebral infarction, seizures, and sepsis. The error was discovered at shift change when the night nurse could not locate the second resident’s medications in the cart. The administrator and DON confirmed that the wrong medications and paperwork had been provided, and the discharging resident’s representative later reported to police that they had received another resident’s private health information, although none of the incorrect medications were taken.

No penalty information released
tooltip icon
The penalty, as released by CMS, applies to the entire inspection this citation is part of, covering all citations and f-tags issued, not just this specific f-tag. For the complete original report, please refer to the 'Details' section.
Failure to Protect Resident PHI During Medication Administration
E
F0583 F583: Keep residents' personal and medical records private and confidential.
Short Summary

Surveyors found that during medication administration, two RNs repeatedly left an electronic medical record screen open and visible on the med cart while entering resident rooms, exposing protected health information (PHI). For multiple residents with complex conditions such as diabetes, CHF, dementia, cerebral palsy, acute kidney failure, depression, and urinary issues, the EMR displayed names, room numbers, diagnoses, and medications and was not locked or secured. Both RNs confirmed in interviews that they did not lock the computer screens before leaving the cart, resulting in PHI being viewable to anyone passing by.

No penalty information released
tooltip icon
The penalty, as released by CMS, applies to the entire inspection this citation is part of, covering all citations and f-tags issued, not just this specific f-tag. For the complete original report, please refer to the 'Details' section.
Unattended Laptop Exposed Resident PHI at Nurses’ Station
D
F0583 F583: Keep residents' personal and medical records private and confidential.
Short Summary

An unattended medication cart laptop at the nurses’ station was left open to a cognitively intact resident’s electronic record, displaying PHI including the resident’s photo, name, gender, room number, date of birth, code status, allergies, and recent vital signs. The cart and laptop were unattended in a common area, allowing anyone passing by to view the information. An LPN confirmed the laptop was left open with visible PHI, despite a facility policy assigning staff responsibility to prevent unauthorized disclosure of PHI.

No penalty information released
tooltip icon
The penalty, as released by CMS, applies to the entire inspection this citation is part of, covering all citations and f-tags issued, not just this specific f-tag. For the complete original report, please refer to the 'Details' section.
Failure to Protect Resident Health Information Privacy in Public Areas
D
F0583 F583: Keep residents' personal and medical records private and confidential.
Short Summary

Staff failed to protect resident health information privacy by discussing medical conditions and treatment plans in public areas. A nurse practitioner and an RN discussed one resident’s medications in a hallway and assessed another resident’s ankle pain and new medication orders at a table in an activities room while other residents were present, without seeking the resident’s preference or moving to a private area. During a meal, a speech therapist questioned a resident with cognitive issues about a recent doctor’s appointment in a crowded dining room and then loudly asked an LPN across the room for details, prompting the LPN to describe the appointment within earshot of other residents and visitors, contrary to the facility’s privacy policy.

No penalty information released
tooltip icon
The penalty, as released by CMS, applies to the entire inspection this citation is part of, covering all citations and f-tags issued, not just this specific f-tag. For the complete original report, please refer to the 'Details' section.

65.1% of Ohio facilities received at least one citation during their inspection in the last 12 months.Will yours be survey-ready?

Surveyors issued 55 serious citations across Ohio in the last 12 months. See exactly what they're citing.

Get ready for your next survey

See what surveyors are citing in Ohio and spot your risk areas before they do.

Monthly Citation Reports

Have you been cited for this tag?

Save hours drafting a compliant Plan of Correction — AI built on real approved POCs.

Plan of Correction Writer

Trusted data from CMS and state health departments

Every citation, penalty and Plan of Correction is sourced from public CMS records (latest release May 27, 2026) and official state health department websites — never guesswork.

Trusted by long-term care providers and associations.

Allegria Senior Living logo
FHCA logo
WeCare Centers logo
Care Rehab logo
An unhandled error has occurred. Reload 🗙