Failure to Safeguard Resident Health Information in External Communication
Penalty
Summary
The facility failed to maintain the confidentiality of a resident's private health information. Specifically, a written communication from the facility to the Better Business Bureau (BBB), a private non-governmental organization, included the resident's name, diagnoses, weights, prescribed medications, and other confidential information. This action was taken in response to a complaint made by the resident's family to the BBB. The facility's administrator confirmed that the response, which contained private health information, was sent to the BBB after consulting with the corporate office. The resident involved had an admission date of 04/29/21 and a discharge date of 05/14/25, with medical diagnoses including end stage renal disease, type two diabetes mellitus, and congestive heart failure. The Minimum Data Set (MDS) assessment indicated the resident had moderately impaired cognition and required supervision with activities of daily living. The facility's policy on confidentiality, dated October 2017, stated that personal and medical records would be safeguarded and access would be limited to authorized staff and business associates. Despite this policy, the facility disclosed confidential information to an unauthorized external entity.