Hospital Fined $250,000 For Late Reporting of Data Breach
A hospital can be fined up to $250,000 for a breach itself. However state law says the combined fine for failing to report a breach and the penalty for the breach itself cannot exceed $250,000, Montano said.
The state's medical record confidentiality laws were enacted in 2008 after hospital medical records of celebrities such as the late Farrah Fawcett and Britney Spears were inappropriately accessed and distributed. A two-bill combination requires health facilities to adopt appropriate administrative, physical and technical safeguards to prevent unauthorized access or unlawful access, use, or disclosure.
Under that breach statute, the total fines as of last June 11 were $1.12 million, levied against eight hospitals.
One of those fines involved the violation of medical records of pop star Michael Jackson at Ronald Reagan UCLA Medical Center. Last year, Kaiser Permanente Hospital in Bellflower was fined for two separate breaches involving the medical records of Nadya "Octomom" Suleman and her octuplets. Those fines totaled $250,000 and $187,000.
Cheryl Clark is senior quality editor and California correspondent for HealthLeaders Media. She is a member of the Association of Health Care Journalists.
- Ratcheting Up Patient Experience Has a Downside
- Narrow Networks Enjoying a Resurgence
- 'Mega Boards' Could be Rural Healthcare Disruptor
- 12 Hires to Keep Your Hospital Out of Trouble
- HL20: Lee Aase—Who's Behind @MayoClinic
- Meaningful Use Payment Adjustments Begin
- HL20: Anne Wojcicki—Unlocking Consumer Access to Genetics
- Taming Time and Moving Healthcare Data
- Christmas Tree Syndrome Season Underway
- Physicians Trained in High-Cost Regions Spend More