Failure to Secure Resident PHI in Public Areas
Penalty
Summary
The facility failed to maintain the confidentiality and security of resident Protected Health Information (PHI) for two residents. Specifically, a resident's code status document containing PHI was observed uncovered and unsecured in a clear wall-mounted mailbox located in a hallway accessible to staff, residents, and visitors. Additionally, documents such as advance directives and a signed Do Not Resuscitate order were left exposed in the same mailbox, making sensitive information easily accessible and not in compliance with facility policy. Further, a staff member left a computer on wheels (COW) unattended in a common area with the screen displaying a resident face sheet, including the resident's name, photograph, and medical details. The Assistant Director of Nursing was observed later securing the computer and closing the resident's chart. Interviews with facility staff and leadership confirmed that these actions were not in accordance with facility policy or HIPAA regulations, and that PHI should not have been left visible or unattended in these areas.