Several Employees of Claxton-Hepburn Medical Center Sacked due to Inappropriate PHI Access

by | Oct 3, 2018

A not-for-profit 115-bed community hospital in Ogdensburg, NY, Claxton-Hepburn Medical Center has sacked several employees for accessing patient health records without official permission.The PHI breaches were identified during an internal review. It is not yet obvious whether that investigation was initiated following a complaint that had been submitted or if the patient privacy violations were uncovered during a regular audit of PHI access logs – A requirement of HIPAA.

Claxton-Hepburn Medical Center has not publicly disclosed how many staff members were sacked in relation to the violations, only reporting that all staff members who purposely committed the acts were sacked. It is also currently unclear the exact number of patients’ PHI was exposed.

Claxton-Hepburn Medical Center has stated that training is given to all staff members on the first day of employment going through the requirements of HIPAA and the importance of safeguarding the privacy of patients. All staff members are made aware that accessing patient health information is only allowed when PHI needs to be viewed to complete work duties or when patient records need to be refreshed, as per the requirements of the HIPAA Privacy Rule. Staff members are also made aware that any unpermitted accessing of PHI will lead to disciplinary steps being applied. It would have been known by the staff members in question that their actions were not allowed under HIPAA Rules.

The identification of the privacy breaches has lead to the hospital putting in place additional security measures to minimise the chance of future HIPAA violations of this nature happening. Claxton-Hepburn Medical Center has also alerted all patients by mail whose records were inappropriately shared or viewed.

While criminal charges could be could potentially be pressed against healthcare staff members for HIPAA Privacy Rule violations, on this occasion Claxton-Hepburn Medical Center has not contacted law enforcement agencies.

Raise the level of HIPAA Awareness in your organization with Learner-Friendly, Comprehensive and Affordable HIPAA Training.

COMPREHENSIVE HIPAA TRAINING

Ryan Coyne

Ryan Coyne is a results-driven leader in the healthcare compliance industry, specializing in regulatory compliance, compliance training, and assisting healthcare organizations and business associates in achieving and maintaining compliance. With a deep knowledge of healthcare regulations and a keen understanding of the challenges faced by the industry, Ryan has developed a reputation as a trusted advisor and advocate for ethical and compliant practices in healthcare. Ryan has successfully advised and guided numerous healthcare organizations, business associates, and healthcare professionals on achieving and maintaining compliance with regulatory training requirements. Ryan's professional focus is using his in-depth expertise and leading a world class team of subject matter experts at ComplianceJunction in regulatory compliance to help organisations navigate the complex landscape of ensuring staff adhere to healthcare regulations. You can connect with Ryan via LinkedIn and follow on Twitter

Raise the level of HIPAA Awareness in your organization with Learner-Friendly, Comprehensive and Affordable HIPAA Training.

Comprehensive HIPAA Training

Used in 1000+ Healthcare Organizations and 100+ Universities

    Full Course - Immediate Access

    Privacy Policy