Failure to Protect Resident PHI in Email Communications
Summary
The facility failed to keep residents’ personal and medical records private and confidential for 3 of 3 residents reviewed. For Resident #1, the record showed admission with cognitive communication deficit and mild cognitive impairment of uncertain etiology, and he was his own responsible party. The record contained no authorization for release of information, yet the social worker’s email list showed a nonresident name as the recipient for Resident #1’s information. Resident #2 was admitted and readmitted, was her own responsible party, and had diagnoses including cognitive communication deficit, personal history of TIA, and cerebral infarction without residual deficits. Her record also had no authorization for release of information on file, and the social worker’s email list showed a nonresident name as the recipient for Resident #2’s information. Resident #3 was admitted with hemiplegia and hemiparesis following cerebral infarction affecting the right dominant side, was his own responsible party, had no authorization for release of information on file, and the social worker’s email list showed a nonresident name as the recipient for Resident #3’s information. During interview and record review, the social worker stated she sent a welcome letter within three days and 7-day clinical information unless a specific date was determined, and that managed care residents received an outcome prediction and current orders were sent to the email on file. She stated she did not encrypt the messages because some families had difficulty opening email, and she was not aware of a family and/or resident signing a health release form. The surveyor observed an email sample containing a welcome letter, advance directive handout, notice of nondiscrimination, your rights in a nursing facility, current orders, and a home and community care transition prediction outcome with patient evaluation information, care needs at the NF/SNF, and anticipated discharge information. The MRD stated an authorization for release of information had to be completed before resident personal information could be released, and the facility policy stated each resident has the right to confidential treatment of medical records and may approve or refuse their release to an individual outside the facility.
Penalty
Resources
Below are regulatory guidelines relevant to this citation:
Trusted data from CMS and state health departments
Every citation, penalty and Plan of Correction is sourced from public CMS records (latest release July 29, 2026) and official state health department websites — never guesswork.
In your survey window? See what surveyors are citing.
The Survey-Prep Report maps your facility's risk from 12 months of CMS and state citation data — what's being cited around you and what to check first. $129 one-time.