Kaiser Permanente employee inappropriately accessed EHR — 8,000 patients affected

Kaiser Foundation Health Plan of the Mid-Atlantic States notified 8,556 patients that some of their information was compromised due to an employee inappropriately accessing portions of its electronic health records.

Advertisement

On Sept. 21, Kaiser Permanente learned that one of its employees inappropriately accessed portions of medical records for patients in the Mid-Atlantic region without proper reason, according to Nov. 18 breach notification from Kaiser. 

An investigation into the incident determined that the unauthorized access was outside the scope of the employees “permissible job functions.”

Patient information the employee accessed include names, medical record numbers, addresses, email addresses, phone numbers and dates of birth.In some cases, medical information and photos were also viewed.

Kaiser said no Social Security numbers or financial information were involved in the breach, and said it believes that the information has not been used or shared to commit fraud or any other criminal activities.

It has sent out letters to the 8,556 individuals impacted by the breach and has terminated the employee. 

At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.

Advertisement

Next Up in Cybersecurity

Advertisement

Comments are closed.