The HIPAA Journal is the leading provider of news, updates, and independent advice for HIPAA compliance

Kaiser Permanente Fined $450,000 for CMIA Violations Due to Mailing Error

Kaiser Permanente has been fined $450,000 by the California Department of Managed Care (CDMC) for impermissibly disclosing the confidential and protected health information (PHI) of up to 167,095 health plan members. Between October 2019 and December 2019, Kaiser Permanente sent 337,755 mailings to enrollees of its health plan; however, an error updating its electronic medical record system resulted in some mailings being sent to outdated addresses.

Kaiser Permanente was contacted by 8 individuals who said they had opened the packets but realized that they were not the intended recipients and 1,788 of the packets were returned unopened as the recipients realized they had been sent to the wrong addresses. The mailings were sent to 167,095 enrollees and Kaiser Permanente could not be sure that those mailings had been received by the intended recipients, which meant thousands of enrollees’ PHI may have been impermissibly disclosed.

CDMC investigated the reported breach and determined there had been an unauthorized disclosure of medical information and negligent maintenance or disposal of medical information, both of which violated the California Confidentiality of Medical Information Act (CMIA). On November 11, 2019, Kaiser Permanente became aware that an error in its electronic medical record system that had resulted in a data breach but failed to stop the mailings until December 20, 2019, 39 days after the error was discovered. As a result of that failure to act, a further 175,000 mailings were potentially sent to incorrect addresses.

In addition to the financial penalty, Kaiser Permanente has agreed to take corrective actions to prevent further data breaches of this nature, including updating its software systems, conducting periodic checks to confirm addresses are in synch, and system checks to ensure it is using the most current physical and/or mailing addresses. Kaiser Permanente will also work with its call center employees to confirm address information, will notify all affected individuals, and will provide refresher training to its staff on the legal standards of the Health Insurance Portability and Accountability Act (HIPAA) concerning the protection of PHI.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

“Health plans must protect the confidentiality of enrollee records and maintain and dispose of medical information correctly,” said DMHC Director Mary Watanabe. “Kaiser Permanente agreed to take corrective actions to protect consumers’ confidential information and ensure this doesn’t happen again.”

Author: Steve Alder is the editor-in-chief of HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist