Violation Of HIPAA Privacy Policy To safeguard All Protected Health Information (PHI) Leads To Fine Of $800,000 For Park-view Health System, Inc.

24 Jun 2014

Violation Of HIPAA Privacy Policy To safeguard All Protected Health Information (PHI) Leads To Fine Of $800,000 For Park-view Health System, Inc.

Park-view Health System, Inc. has agreed to settle potential violations of the HIPAA Privacy Rule with the U.S. Office for Civil Rights (OCR). Parkview will pay $800,000 and adopt a corrective action plan to address deficiencies in its HIPAA compliance program. Park-view will review & update its HIPAA privacy policies and ensure all employees are trained with the HIPAA Privacy policies and procedures to ensure that similar violations don’t occur.

OCR opened an investigation after receiving a complaint from a retiring physician alleging that Parkview had violated the HIPAA Privacy Rule. On June 4, 2009, Park-view employees, with notice that the physician was not at home, left 71 cardboard boxes of these medical records unattended and accessible to unauthorized persons on the driveway of the physician’s home, within 20 feet of the public road and a short distance away from a heavily trafficked public shopping venue.

As a covered entity under the HIPAA Privacy Rule, Park-view must appropriately and reasonably safeguard all protected health information in its possession, from the time it is acquired through its disposition.

“All too often we receive complaints of records being discarded or transferred in a manner that puts patient information at risk,” said Christina Heide, acting deputy director of health information privacy at OCR. “It is imperative that HIPAA-covered entities and their business associates protect patient information during its transfer and disposal.”

Parkview cooperated with OCR throughout its investigation. In addition to the $800,000 resolution amount, the settlement includes a corrective action plan requiring Park-view to revise their HIPAA Privacy forms and procedures, provide HIPAA Privacy training to employees, and provide an implementation report to OCR.
OCR offers helpful FAQs concerning HIPAA and the disposal of protected health information:

The Resolution Agreement can be found at: http://www.hhs.gov/ocr/privacy/hipaa/enforcement/examples/parkview.html