NY hospital waits 15 months to report breach
A New York hospital on March 1 began notifying patients and the Office for Civil Rights (OCR) about a data breach dating back to November 2011.
The Samaritan Hospital, Watertown, N.Y., may eventually face hefty fines from the OCR for the significant notification delay.
A nursing supervisor at the Rensselaer County jail improperly accessed the hospital’s patient records, triggering the investigation. The hospital notified the sheriff about the breach and disabled the access of the individual whom they believed improperly accessed the information.
According to various news outlets, the sheriff told the hospital not to notify patients or the OCR so as not to impede the investigation. Some 14 months later, the sheriff’s office has authorized Samaritan Hospital to notify the patients.
Because Samaritan Hospital provides treatment for inmates, the jail’s nursing staff has access to Samaritan’s EHRs for the purposes of coordinating care.
Reports indicate that approximately two dozen patients were impacted by the breach.