Unsecured Laptop Screen Exposed Residents’ Electronic Health Information
Summary
The deficiency involves a failure to maintain the privacy and confidentiality of residents’ personal and medical records when an open laptop displaying electronic health records was left unattended in a common area. During initial rounds, a surveyor observed a laptop on a crash cart with the Matrix electronic health record platform open and showing several residents’ information on the screen. The Assistant Director (AD) acknowledged that the laptop was hers and explained that she had left it open when she responded to a resident yelling for help, stating she did not think to shut the laptop at that time. In interviews, multiple staff members confirmed that the facility’s expectation and practice are that laptop screens displaying resident information must be closed or locked whenever staff step away. An LPN with five years of experience stated that she always locks the screen when leaving the laptop and recognized that leaving resident information visible is a HIPAA violation. A CNA and an RN both reported that laptop screens should never be left open with resident information visible, that anyone walking by could see the information, and that if they observed such a situation, they would close the laptop and remind the staff member. Both indicated they had received in‑service training on HIPAA, resident rights, and confidentiality within the past one to three months. The DON and Administrator also confirmed that staff are responsible for securing laptops with resident information and that leaving screens open with PHI visible is considered a HIPAA violation. The DON stated that her expectation is that staff shut or lock screens when walking away and that she had not personally witnessed staff leaving laptops open. The Administrator reported being told that the AD left the laptop open when responding to a resident calling for help and acknowledged that an open laptop could allow others, including a state worker, to access residents’ information. Review of the facility’s Health Information Management Policies and Procedures, revised on 4‑29‑2022, showed that PHI must not be used or disclosed in a manner that violates HIPAA, must not be posted or displayed in public locations, and that all employees must safeguard electronic PHI, limiting access and disclosure to the minimum necessary.
Penalty
Resources
Below are regulatory guidelines relevant to this citation:
Trusted data from CMS and state health departments
Every citation, penalty and Plan of Correction is sourced from public CMS records (latest release July 29, 2026) and official state health department websites — never guesswork.
In your survey window? See what surveyors are citing.
The Survey-Prep Report maps your facility's risk from 12 months of CMS and state citation data — what's being cited around you and what to check first. $129 one-time.