Question
Following the laptop theft, Compliant Hospital determines that it must contact the affected patients to notify them of the incident in accordance with HIPAA. The
Following the laptop theft, Compliant Hospital determines that it must contact the affected patients to notify them of the incident in accordance with HIPAA. The Hospital assembles a response team and designates several staff members to contact patients. One staff member is designated to contact patient Otto Dempsey. The staff member consults the Hospital's records and sees that Mr. Dempsey filed a written request for privacy protection to have communications about his health care and protected health information made in writing and sent to his mother's address. The staff member is concerned that the situation is urgent and that mailing a notice letter to Mr. Dempsey will take too long. She instead attempts to contact Mr. Dempsey at the phone number listed in his electronic health records. The staff member calls the listed number several times but cannot reach Mr. Dempsey. She finally decides to leave a message, and says the following:
"Hello, Mr. Dempsey, I am calling from Compliant Hospital to notify you that, on January 12, 2022, a theft occurred and resulted in the loss of a laptop computer containing medical records, including yours. The Hospital conducted a thorough audit and determined that the laptop contained your insurance information and records related to your treatment at the hospital's outpatient behavioral health clinic. We regret having to notify you of this event, and assure you that the confidentiality of your health information is our highest priority. Please rest assured that records of your counseling sessions and antipsychotic medications remain available at the clinic, and your provider looks forward to seeing you at your next visit. Please contact the Hospital if you have any questions about this notification. Compliant Hospital appreciates your understanding."
The staff member who left the message did not realize that Mr. Dempsey lives in a transitional halfway house for individuals recovering from drug and alcohol addiction. The staff member was also unaware that she left a message for Mr. Dempsey on the facility's shared voice message system, which all residents may access. When he returns to the house later that day, Mr. Dempsey is confronted by several fellow residents who tease him about being crazy. They ask him if he hears voices or has imaginary friends. Mr. Dempsey feels humiliated. The first thought that goes through his mind is: "I need a drink."
Address the following questions:
- Did the Compliant Hospital staff member violate the Privacy Rule by calling Mr. Dempsey? Justify answer
- Did the message that the Compliant Hospital staff member left for Mr. Dempsey violate the Privacy Rule? Justify y
- In response to the incident, Mr. Dempsey requests access to his health records to see for himself what they contain. Compliant Hospital is located in the state of New Texzona, which has a patient privacy law that is similar to HIPAA. The New Texzona law requires a Covered Entity to give patients access to their health records within 10 business days of receiving a request. HIPAA, in contrast, requires a Covered Entity to act on a request for access within 30 days. Which deadline should Compliant Hospital honor? What analysis must you conduct to answer this question? Justify
Step by Step Solution
3.34 Rating (154 Votes )
There are 3 Steps involved in it
Step: 1
1 Privacy Rule Violation by Calling The Compliant Hospital staff member did not violate the Privacy ...Get Instant Access to Expert-Tailored Solutions
See step-by-step solutions with expert insights and AI powered tools for academic success
Step: 2
Step: 3
Ace Your Homework with AI
Get the answers you need in no time with our AI-driven, step-by-step assistance
Get Started