The California Department of Public Health imposed the fine after determining that the medical center had five deficiencies related to the unauthorized disclosure of medical information on a diabetes patient treated there in 2010. According to the report, the patient’s medical files were shared with journalists when Shasta Regional was seeking to respond to a story published by California Watch, a non-profit news organization that featured the patient, Darlene Courtois, and allegations that the hospital was overbilling Medicare. In addition, an email about the patient’s treatment was sent to 785 employees.
Prime Healthcare appealed the state’s findings and penalties, citing Shasta Regional’s belief that the disclosers were permitted under federal and state law.
More Articles on Privacy Violation Fines:
University of Arkansas for Medical Sciences Notifies 1,500 Patients of Data Breach
Alaska Medicaid Settles HIPAA Security Case for $1.7M
Proposed HIPAA Rule Would Fine Health Provider Partners Up to $1.5M for Privacy Violations
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.