Improper Release of PHI: A staff member released a resident’s requested medical records to the resident’s son, but the packet also included skilled progress notes and other PHI for 12 unrelated residents. The error occurred when the staff member printed records from the EMR using only the first few letters of the resident’s name and did not recognize that multiple residents’ documents had been selected before sending the scanned records by secure email.
Failure to maintain privacy during wound care. An RN left the blinds open to a window facing the parking lot while completing a sacral dressing change for a resident with intact cognition and significant ADL dependence. The resident’s partially naked body was visible from outside, and the resident stated she wanted the blinds closed during treatment. Facility policy required a closed door, a drawn curtain, or both during personal care and treatment procedures.
Failure to maintain privacy during incontinence care: A resident with multiple diagnoses, including dementia and psychiatric conditions, was incontinent and required transfer to bed for care. Two CNAs removed soiled clothing and provided care with the bed near an exterior window and the curtains left open, exposing the resident’s perinium and buttock while an LPN applied barrier cream; the CNAs confirmed the resident was not given sufficient privacy.
Unsecured Resident Medical Records Found in Open Rooms: Surveyors observed resident medical records stored on surfaces in an open, unlocked room and in another room with the door wide open, including an open binder with medical records and COVID vaccination information. An LPN stated the former memory care unit doors were never locked after closure, and the administrator confirmed that two rooms contained resident medical records and were left unlocked and open despite the facility having a dedicated medical records room.
Failure to Maintain Resident Privacy During Assessments, Insulin Administration, and Record Access: A NP assessed three residents in a public dining area with other residents and staff nearby, and an RN performed blood glucose testing and gave insulin to a resident at a dining table while the resident was eating. In a separate event, an open eMAR on a med cart exposed residents' names, photos, and room numbers until the DON closed it; staff confirmed the privacy breaches.
Surveyors found that during a morning med pass on one hall, RNs repeatedly left a medication cart laptop open with the electronic charting system visible and accessible while walking away to administer meds in resident rooms. A staff member confirmed the laptop remained open and unsecured even as a resident ambulated nearby. In interviews, an RN acknowledged not following the expected practice of minimizing the charting system and closing the laptop screen, and facility leadership confirmed there was no formal written policy on securing laptops when staff left the med cart, despite an expectation that screens be closed to prevent visibility.
A resident with moderate cognitive impairment and multiple medical conditions had a designated healthcare and financial POA, but the facility provided the resident’s face sheet to an outside contractor without obtaining written authorization from the POA, contrary to its HIPAA policy. The POA reported she did not consent to the disclosure and that the contractor contacted the resident’s bank and insurance company without her approval. The resident, who reported significant memory issues, was unaware her information had been shared and later expressed feeling unhappy and uneasy about the unauthorized access, while the contractor confirmed receiving the face sheet from the facility.
A cognitively intact, fully dependent and always incontinent resident received incontinence care from a CNA in a shared room without the privacy curtain being drawn, despite the roommate being present. During the care, the resident’s genital area and buttocks were exposed while the CNA removed the adult brief and cleaned the resident. The resident later reported that staff sometimes forget to pull the curtain and that this exposure sometimes bothers him, and the CNA acknowledged not using the privacy curtain, contrary to facility policy on resident privacy during personal care.
A cognitively intact resident with Huntington’s disease and other conditions was participating in chair exercises when a CNA used a personal cellphone to record the resident lifting her leg above her head, without any signed photo release or consent from the resident’s POA. Two other CNAs watched the event and did not report it. Other staff later observed the CNAs laughing and viewing the image on the phone. Review of incident reports, staff statements, and the facility’s social media policy confirmed that the recording was taken in the work area using a personal device and that facility policy prohibits taking or sharing resident photos or videos without prior written permission.
A resident who was cognitively intact and required supervision with ADLs was discharged, and an LPN mistakenly sent that resident’s representative home with another resident’s medications and written discharge instructions, which included detailed information on multiple prescribed drugs for serious conditions such as cerebral infarction, seizures, and sepsis. The error was discovered at shift change when the night nurse could not locate the second resident’s medications in the cart. The administrator and DON confirmed that the wrong medications and paperwork had been provided, and the discharging resident’s representative later reported to police that they had received another resident’s private health information, although none of the incorrect medications were taken.
Self-audit
Pick a level of detail and, optionally, what to focus on — then generate a survey-ready checklist distilled from the most recent citations.
Beta · AI-generated — for reference only, not professional advice. Verify against current CMS guidance before relying on it. Assisto accepts no responsibility for how this checklist is used.
Citations used to create this checklist
Trusted data from CMS and state health departments
Every citation, penalty and Plan of Correction is sourced from public CMS records (latest release July 29, 2026) and official state health department websites — never guesswork.
In your survey window? See what surveyors are citing.
The Survey-Prep Report maps your facility's risk from 12 months of CMS and state citation data — what's being cited around you and what to check first. $129 one-time.