Breadcrumb

Episodes of Non-Adherence to Privacy and Security Policies at the Tibor Rubin VA Medical Center, Long Beach, California

Report Information

Issue Date
Report Number
17-03557-177
VISN
State
California
District
VA Office
Veterans Health Administration (VHA)
Report Author
Office of Healthcare Inspections
Report Type
Hotline Healthcare Inspection
Recommendations
6
Questioned Costs
$0
Better Use of Funds
$0
Congressionally Mandated
No

Summary

Summary
The VA Office of Inspector General (OIG) conducted an inspection in response to episodes of non-adherence to Veterans Health Administration (VHA) and VA policies on patient information privacy and security at the Tibor Rubin VA Medical Center, Long Beach, California. After a VA computer update, a facility diagnostic device no longer interfaced with VHA patients’ electronic health records. A facility provider developed and implemented two workarounds to continue using the device. The workarounds were not in accordance with VHA and VA privacy and security policies and included using personal emails, a laptop, a non-encrypted flash drive, and electronic storage that were not approved by the VA. The OIG determined that the facility security and privacy staff mitigated the use of the workarounds and deleted the emails and information from the personal devices. However, issues with staff text messages were not addressed and, according to VA policy, the unencrypted personal emails and text messages did not meet the VA matrix criteria for a breach. The OIG concluded that patient sensitive personal information was at risk for disclosure to outside sources. Although the VA handbook that addressed matrix guidance for sensitive personal information incidents and events was revised on March 29, 2019, it did not address issues identified in this report. The OIG determined that 133 patients had sensitive personal information stored in unencrypted emails or text messages. In addition, facility staff used prohibited logbooks to track patient information and testing equipment. The OIG made one recommendation to the VA Assistant Secretary for Information and Technology and five recommendations to the Facility Director related to communication and education, disclosure of protected patient information, VA policy review, and compliance with the use of logbooks.

Open Recommendation Image, SquareOpenClosed and Implemented Recommendation Image, CheckmarkClosed-ImplementedNot Implemented Recommendation Image, X character'Closed-Not Implemented
No. 1
Closed and Implemented Recommendation Image, Checkmark
to Veterans Health Administration (VHA)
The Tibor Rubin VA Medical Center Director reviews the communication processes between employees and Biomedical Engineering and Information Technology departments regarding disclosure of patient sensitive information when interface issues exist and takes necessary actions to improve this communication.
No. 2
Closed and Implemented Recommendation Image, Checkmark
to Veterans Health Administration (VHA)
The Tibor Rubin VA Medical Center Director ensures that facility healthcare staff can identify which patient information or combination of patient information is considered protected from disclosure and staff transfers protected information across all communication modes, including emails and text pages, according to VA/Veterans Health Administration policy.
No. 3
Closed and Implemented Recommendation Image, Checkmark
to Veterans Health Administration (VHA)
The Tibor Rubin VA Medical Center Director ensures that the Privacy Officer and the Information Systems Security Officer take necessary steps when protected patient information is compromised or possibly breached.
No. 4
Closed and Implemented Recommendation Image, Checkmark
to Veterans Health Administration (VHA)
The Tibor Rubin VA Medical Center Director considers offering credit monitoring to the 133 identified patients.
No. 5
Closed and Implemented Recommendation Image, Checkmark
to Information and Technology (OIT)
The VA Assistant Secretary for Information and Technology reviews and adjusts the Veterans Administration Handbook 6500.2, Management of Breaches Involving Sensitive Personal Information, to include a process and guidance to address sensitive personal information incidents and events such as the use of personal email systems to transfer and store patient sensitive information and texting with personal cell phones.
No. 6
Closed and Implemented Recommendation Image, Checkmark
to Veterans Health Administration (VHA)
The Tibor Rubin VA Medical Center Director reviews the facility’s policy and use of physical logbooks and ensures compliance with Veterans Health Administration policy.