Unsecured Computer Screen Exposes Resident Health Information
Penalty
Summary
A deficiency occurred when a nurse (LVN B) left a computer at the nursing station unattended with a resident's clinical information displayed on the screen. The information, which included sensitive health details such as diagnoses of hypothyroidism, hypertension, gastro-esophageal reflux disease, and breast cancer, was visible in the electronic health record system (Point Click Care). This action was observed during a survey, and it was noted that the computer screen was not minimized or locked, leaving the resident's personal health information accessible to anyone passing by, including visitors and other residents. Interviews with the nurse revealed that he did not routinely minimize or lock the computer screen when stepping away, relying instead on the computer's automatic screen-off function. He acknowledged receiving HIPAA training at hire and annually, and understood the responsibility to secure the screen. Facility leadership, including the ADON and Administrator, confirmed that policy requires staff to minimize or lock screens when leaving computers unattended, and that monitoring is conducted through observation rounds. Documentation showed that the nurse had attended and acknowledged HIPAA training, which included instructions on protecting patient information.