Improper Disposal of Medical Records Breaches Resident Confidentiality
Penalty
Summary
The facility failed to maintain personal privacy and confidentiality of residents' personal and medical records by disposing of protected health information (PHI) in a public dumpster. This incident involved 136 residents, with medical records dating from 2008 to 2018 being placed in closed boxes and discarded off-site at a laundry building. The boxes were labeled with residents' names and years, making the information easily identifiable. The maintenance director was responsible for placing the records in the dumpster, and the administrator was notified of the breach after the records were discovered. Interviews revealed that the maintenance director was not aware of HIPAA regulations at the time of the incident and mistakenly disposed of the records in the dumpster. Other staff members, including an LPN and a housekeeper, demonstrated awareness of HIPAA requirements and stated that protected information should be placed in designated shred boxes or given to a charge nurse for proper disposal. The facility's policies required that PHI be managed and protected to prevent unauthorized release or disclosure, but these procedures were not followed in this instance, resulting in a breach of confidentiality.