Failure to Secure Electronic PHI Exposes Resident Information
Penalty
Summary
Surveyors observed multiple instances where residents' personal and medical information was left visible and unsecured on computer screens throughout several neighborhoods in the facility, including Bluegrass Way, Platinum Ridge, Boulder Creek, and Arrowhead Trail. Computers on rolling stands and at nurses' stations were found with screens open to sensitive resident information, such as medical records and medication lists, while unattended by staff. In several cases, the screens were positioned so that information could be viewed from the hallway, and it was not always clear which staff member was logged in at the time. These observations occurred both inside resident rooms and in common areas, with no staff present to monitor or secure the information. Interviews with staff, including an LPN, RN coordinator, and the DON, confirmed that the expectation was for computer screens to be closed or locked when not in use to protect resident privacy. The facility's policy on safeguarding protected health information (PHI) requires staff to log off or lock workstations when leaving the area and to position monitors to prevent unauthorized viewing. Despite these policies, staff failed to consistently secure electronic PHI, resulting in multiple breaches of confidentiality as observed by surveyors.