Home ▸ Law ▸ Other Law
»
Hipaa violation? Dentist office released personal records to unknown email account
Hipaa violation? Dentist office released personal records to unknown email account
Asked Feb 28, 2011, 11:04 AM
—
7 Answers
I recently asked my dental office to email me a copy of my treatment plan as I had some questions regarding fees. I confirmed my correct email address on paper at the office, on the phone with the office, and in an email sent their account. I was told the next day that my plan was sent to a completely different email address, who's they don't know. The plan contained my full name, address, date of next appt., how much I had paid for a procedure, treatments I had scheduled, and the chart number. When I spoke to the office manager she said a typo had been made which is absolutely ridiculous since the email address I have and the email they sent my records to is completely different. What are my options? I'm filing a complaint with the state board and I'm going to ask to office to refund fees I had already prepaid as I don't feel comfortable continuing treatment with them. What type of attorney should I speak to regarding this matter? I'm not looking to benefit financially, my main concern is protection against identity theft.
First, while this may be a HIPAA violation it does not appear to be a deliberate one. So I doubt if the state board or HIPAA will do anything about it.
Second, I would not waste my time hiring an attorney as there is nothing to sue over that I can see.
Third, I see no reason to refund fees for work done. What happened does not affect the work done. While I understand not wanting to continue with that office, but you can have your records handed to you and take it to a new dentist.
Finally, what I WOULD do is ask that they pay for a credit monitoring service for a year to make sure the info that was sent is not used for identity theft.
We'd like to understand what you find wrong with ScottGem's answer:
What's inaccurate about this answer? Say it in 25 words or less here and/or reply in the thread with more detail.
Please focus on the content not the person!
Link to a credible and well-known source. You can provide a URL or simply describe the source.
...Finally, what I WOULD do is ask that they pay for a credit monitoring service for a year to make sure the info that was sent is not used for identity theft.
Quote:
Originally Posted by joansmith71
... The plan contained my full name, address, date of next appt., how much I had paid for a procedure, treatments I had scheduled, and the chart number.
...
My main concern is protection against identity theft.
How do you imagine that information would facilitate identity theft? I don't see that any credit card or banking information was compromised.
We'd like to understand what you find wrong with AK lawyer's answer:
What's inaccurate about this answer? Say it in 25 words or less here and/or reply in the thread with more detail.
Please focus on the content not the person!
Link to a credible and well-known source. You can provide a URL or simply describe the source.
Thanks you for your feedback. Let me clarify, I'm not asking a refund for services already performed. I've paid in advance for procedures that have yet to be done but I don't feel comfortable staying at that practice. I don't want to sue the practice for damages, it's more to create a record in the event that I experience issues later with identity theft, etc. Same with the state board and hipaa, do you suggest a different approach? And I will definitely ask for credit monitoring, I think that's a more than fair request. Again, thank you for your feedback. I greatly appreciate any and all help!
We'd like to understand what you find wrong with joansmith71's answer:
What's inaccurate about this answer? Say it in 25 words or less here and/or reply in the thread with more detail.
Please focus on the content not the person!
Link to a credible and well-known source. You can provide a URL or simply describe the source.
I'm not asking a refund for services already performed. I've paid in advance for procedures that have yet to be done but I don't feel comfortable staying at that practice.
Ok that's different and understandable.
If you are looking to protect yourself, I think the credit monitoring should be sufficient.
We'd like to understand what you find wrong with ScottGem's answer:
What's inaccurate about this answer? Say it in 25 words or less here and/or reply in the thread with more detail.
Please focus on the content not the person!
Link to a credible and well-known source. You can provide a URL or simply describe the source.
Good advice but I too do not see that anything about your financials was released so I don't see why they would pay to monitor your credit. Sure you get your fees back, the service has not been given. However, how has their mistake damaged you, financially? HIPAA regs mention that an error like this is not a violation
We'd like to understand what you find wrong with ballengerb1's answer:
What's inaccurate about this answer? Say it in 25 words or less here and/or reply in the thread with more detail.
Please focus on the content not the person!
Link to a credible and well-known source. You can provide a URL or simply describe the source.
Yes, you could ask for any unused advanced payment back and perhaps the cost of a credit monitoring service, but that is about it.
I doubt if any government agency will do anything and if they do, merely a letter reminding them to be careful and at most require their clerks to do a few hours of training
We'd like to understand what you find wrong with Fr_Chuck's answer:
What's inaccurate about this answer? Say it in 25 words or less here and/or reply in the thread with more detail.
Please focus on the content not the person!
Link to a credible and well-known source. You can provide a URL or simply describe the source.
http://www.hhs.gov/ocr/privacy/hipaa...nts/index.htmlThis is a violation of HIPAA. All email from HIPAA covered entities (your dentist) containing any ePHI (elctronic Patient Health Information) must be secured and encrypted. In the case of sending electronic information it would require the intended receipient to answer a secure question in order to view any patient information. Any other recipient who did not know the answer to the specified question would not be able to access your patient information. In your case it does not sound like the proper security steps were taken by this dentist (unfortunately this is very common)as such this results in a breach of HIPAA.
You as the patient can file a complaint with the Dept. of Health and Human Services.of the
Here's the link for their site: http://www.hhs.gov/ocr/privacy/hipaa...nts/index.html.
I own an I.T. company specializing in digital integration within private-practice dental and medical offices. I am not sure what else you can legally do to account for the "damages" you incurred however the Dept. of HHS can launch an investigation against the dentist and y stiff fines (cap limits are $1.5 million)....my guess is if this has happened with you its happened with other patients as well.
We'd like to understand what you find wrong with mrmax3007's answer:
What's inaccurate about this answer? Say it in 25 words or less here and/or reply in the thread with more detail.
Please focus on the content not the person!
Link to a credible and well-known source. You can provide a URL or simply describe the source.
I am a front desk receptionist for a dental office. A patient came in, was very friendly, flirty, etc. The next day I got his phone number and sent him a tex message. In the tex, I told him who I was, and that if he was SINGLE and interested then he could call me. We don't have an office policy...
The person at the front desk used my medical records to get my personal number then texted me about 8 times asking if I was single and such. I kept asking whowas this and finally they admitted who they were and where they worked. Is this a hipaa violation? If so, what do I do next?
I have worked at my company (hospital) for 7 years. I left for 9 months then came back and when I came back to work the HR department had to decide how much to pay me based off my years of experience as a nurse. When it came time to give me my salary they said they have no record of me ever...
Thank you in advance for any responses.
A child has been re-admitted to school with appropriate clearance after surgery, but with limitations set forth in a physician?s letter. For clarification, a school nurse called the Physician's office regarding some of the restrictions. As the parent were...