Failure to Protect Resident Health Information Confidentiality
Penalty
Summary
The facility failed to maintain the confidentiality of protected health information (PHI) when a staff member provided an after-visit summary containing personal and medical details of one resident to the family member of a different resident. The summary included the resident's full name, date of birth, medical record number, referrals for further testing, and results of a recent x-ray. The family member who received the document reported the error to the staff member, but the staff member responded indifferently, stating they did not care and did not want the paperwork back, allowing the family member to keep the document. The incident was confirmed through interviews, observation, and record review. The family member retained the after-visit summary and provided it to the surveyor as evidence. The facility's posted resident rights statement included confidentiality, and management acknowledged that only residents, their guardians, or POAs should have access to such records. The administrator stated that, in such cases, staff are expected to retrieve the documents and notify management, but this did not occur in this instance.