Kaiser Permanente Employee Improperly Accessed EHR

Nov. 22, 2022
Kaiser Permanente posted an alert to its website on Nov. 18 regarding an employee inappropriately accessing portions of electronic health records—no social security numbers or financial information were involved

On Nov. 18, Kaiser Foundation Health Plan of the Mid-Atlantic States, Inc. posted an alert to its website regarding a privacy incident for some Kaiser Permanente patients. Letters have been sent to impacted patients, although the alert on the website says that some letters were undeliverable, and the organization was not able to find current addresses for some patients.

The alert says that “On September 21, 2022, Kaiser Permanente determined that one of its employees inappropriately accessed portions of medical records for patients in the Mid-Atlantic region without a reasonable basis. An investigation determined that the former employee’s access was outside the scope of their permissible job functions. We reported these facts to federal agencies to meet our obligations under applicable laws and regulations.”

Further, “No Social Security numbers or financial information were involved in this incident. Additionally, there is no evidence that the accessed information has been used or shared to commit fraud or any other criminal activities. Our investigation determined that demographic information (including name, medical record number, address, email address, contact telephone number(s), and date of birth), and medical information was viewed, and, in some cases, photos were also viewed.”

The alert goes on to explain that the individual responsible is no longer employed at Kaiser Permanente and the incident has been reported to federal agencies. Additionally, the organization is reviewing its policies and procedures surrounding patients’ medical records.

Kaiser Permanente urges patients who would like more information on ways to protect themselves against identity theft to visit the Federal Trade Commission’s Identity Theft website

Sponsored Recommendations

A Cyber Shield for Healthcare: Exploring HHS's $1.3 Billion Security Initiative

Unlock the Future of Healthcare Cybersecurity with Erik Decker, Co-Chair of the HHS 405(d) workgroup! Don't miss this opportunity to gain invaluable knowledge from a seasoned ...

Enhancing Remote Radiology: How Zero Trust Access Revolutionizes Healthcare Connectivity

This content details how a cloud-enabled zero trust architecture ensures high performance, compliance, and scalability, overcoming the limitations of traditional VPN solutions...

Spotlight on Artificial Intelligence

Unlock the potential of AI in our latest series. Discover how AI is revolutionizing clinical decision support, improving workflow efficiency, and transforming medical documentation...

Beyond the VPN: Zero Trust Access for a Healthcare Hybrid Work Environment

This whitepaper explores how a cloud-enabled zero trust architecture ensures secure, least privileged access to applications, meeting regulatory requirements and enhancing user...