A hospital can be fined up to $250,000 for a breach itself. However state law says the combined fine for failing to report a breach and the penalty for the breach itself cannot exceed $250,000, Montano said.
The state's medical record confidentiality laws were enacted in 2008 after hospital medical records of celebrities such as the late Farrah Fawcett and Britney Spears were inappropriately accessed and distributed. A two-bill combination requires health facilities to adopt appropriate administrative, physical and technical safeguards to prevent unauthorized access or unlawful access, use, or disclosure.
Under that breach statute, the total fines as of last June 11 were $1.12 million, levied against eight hospitals.
One of those fines involved the violation of medical records of pop star Michael Jackson at Ronald Reagan UCLA Medical Center. Last year, Kaiser Permanente Hospital in Bellflower was fined for two separate breaches involving the medical records of Nadya "Octomom" Suleman and her octuplets. Those fines totaled $250,000 and $187,000.