Unsecured Storage of Medical Records with Visible PHI in Shared Warehouse
Penalty
Summary
The facility failed to ensure privacy and confidentiality of medical records when surveyors observed resident medical records stored in an unsecured warehouse building. During a dual surveyor observation conducted in connection with a complaint investigation, the Director of Maintenance and Assistant Director of Maintenance unlocked the warehouse, where surveyors saw several open boxes of medical records in different areas of the warehouse with freely visible protected health information, including resident names and medical record assessments. In another area of the warehouse, surveyors observed approximately 11 closed boxes of medical records with papers affixed to the exterior showing visible resident names and medical record numbers, as well as medical record files sitting on top of the boxes with names and other information written on the outside of the files. During the same observation, the Director of Maintenance stated that the warehouse was used by "everybody" to put items in and that it served as additional storage. When surveyors asked who had access to the warehouse, the Director of Maintenance identified the central supply staff, housekeeping, and dietary staff as having access. In a subsequent interview, the DON confirmed that maintenance and environmental services staff did not need access to medical records or protected health information, yet reported that the Maintenance Director, Environmental Services Director, Medical Records/Supply person, and Maintenance Assistant all had keys or access to the warehouse where the medical information was stored. These observations and interviews established that medical records containing protected health information were stored in a location accessible to multiple non-clinical staff, with resident-identifying information openly visible.
