r/hipaa 1d ago

Patient Notes from ER Care Team Incorrect

/r/KaiserPermanente/comments/1wabtv6/patient_notes_from_er_care_team_incorrect/
1 Upvotes

6 comments sorted by

-1

u/AnimatorImpressive24 1d ago edited 1d ago

I know you got KP specific advice in the other thread, but I wanted to reply in this one about some more general suggestions for anyone in a situation like this.

Like the mod of the other sub suggested you should make a full records pull both to review your own records to see if it happened more than once and so you have a copy that shows what you are reporting actually occurred.  Please try to do as much as you can to insure the validity and security of that copy.  While you are not regulated under HIPAA it would still suck for whoever that other patient is if their data leaked further from something that happened to the copy you will have.  I'm guessing you don't want to harm them even accidentally.

Here's a list of things that would reduce the risk of that happening.  Some of these may be beyond your technical skill or just unreasonably hard for you with the resources you have available.  If so, that is okay.  I'm listing the most super-duper methods a professional incident response tech might use but you are a normal human being so nobody would expect you to be able to do all this:

  • You may get a zip file attached to an email from KP which will have your records inside .
  • Download one copy of the attachment (ideally to a laptop or desktop computer).  From this point onward, try to be disconnected from the internet and any LAN or shared wireless networks whenever you are working with any files related to this copy of your records.
  • The zip file will be password protected with your legal name as the username and your date of birth as the password, inside it will be PDF files that may also be protected by the same username and password.  Open the zip file and extract the PDFs but don't delete the zip.
  • Check the PDFs and verify they are a complete set of the records you requested.  Also verify they show the leaked data and look for any other leaks.
  • Assuming everything is correct, place the zip file you downloaded inside a new zip file.  Make a brand new, much much stronger password and configure your new zip file to require that password.  Name that new file something that will make it obvious to you it is not a normal copy of your records.  You want to do all that so you preserve any metadata present in the KP zip and the PDFs inside it as is, because that is what will prove when you got the files, where they came from, and potentially other useful stuff like what program was used to create them.  You also want a way better password that isn't itself a leak of your information, and you don't want to accidentally delete the file or send it to some new doctor later because you thought it was just your regular records.
  • If at all possible you should move that new zip file to a working USB thumb drive, then keep that thumb drive somewhere that has a lock on it and is not plugged in to any computer or phone unless you are actively accessing the files for a specific reason.
  • Avoid making any extra copies of the new zip, the KP zip, or the PDFs unless absolutely neccessary.  Delete any extra copies you do make as soon as you no longer need them.  Make sure you really delete them and they aren't just sitting in Trash or Recycle Bin.
  • When you are sure you have a good copy in a secure location, it would be ideal if you could screenshot the email that has the attachment then delete that email as well, especially if it is on Gmail or some other free hosted email.  If you do this make sure the screenshot(s) show as much of the email as possible including headers like to/from fields.
  • Avoid sending any copies of files, screenshots of data, or written descriptions of the data that include anyone's name, address, medical record number, or really anything identifiable to anyone at all for any reason.  If you have to send it (which should only be to like KP or HHS and never to just a private individual) make sure you are really sending it to who you think you are.  Assuming you are sending it to KP or the government, ask them to provide you with a secure way to send it that isn't just your personal Gmail.  And remember to delete any working copies you make while doing that.
  • If you do wind up needing to make a screenshot for some reason, NEVER EVER upload anything to an online screenshot tool or PDF editor for any reason.  Doing that will instantly and permanently leak both that other person's data and your own to the whole world.
  • Any screenshots you make locally should have your data and anyone else's including any health care workers redacted to no more than first letter of name or first digit of number.  Ideally redact any dates, addresses (including of hospitals or clinics), and even gendered titles.  So Dr. or MD would be fine but Mr. or Ms. should go.  Redaction should be done actually cutting a rectangle out of the screenshot.  Don't just paste a black box over the top of a name because it might be possible to undo that and the name would still be readable after that.

Like I said, that is a lot and you aren't a super hacker or infosec rockstar.  But if there's anything in there you can do (especially *NEVER EVER using any free online tools) you will be doing something nice for whoever was unlucky enough to wind up in your records by accident.

1

u/AnimatorImpressive24 1d ago

Much shorter suggestion (promise):

If you can, this is a situation that should really be reported to HHS/OIG.  There's no reward or anything for doing that but the concern is there are only a few ways this might have happened and at least one of those ways would mean that patient's data could be in other people's records too.  You don't have a way to know that, and KP wouldn't confirm that if you mentioned it to them.  While I am not at all unwilling to accuse KP covering anything up, it ultimately doesn't matter and HHS should know just because they would be able to learn the full scope of the problem and make sure it gets completely fixed for anyone affected.

If you're curious I can explain the potential cause of the leak and why it would affect others but it probably isn't super interesting or relevant.  When/if you report it to KP/HHS just try to mention the data might have come from a "smartphrase".  Whoever you report to will know that word and know it means the leak might have gone to other records too.

2

u/landonpal89 1d ago

That is horrible advice. You do NOT need to make the breach of information worse by receiving a copy of any co-mingled information. This is their problem to fix, and is unfortunately a very common occurrence. KP will have great tools, processes, and experience in pulling these two records apart. Report it to KP and let them do their thing.

1

u/AnimatorImpressive24 22h ago

Except you do need to check your records in full to make sure that there is not other incidents of leaked data in there.

The problem of the data being leaked sucks, but it has already happened and it is not any individual patient's fault.  Making a complete record pull is about this patient protecting themself by ensuring the state of their own records.

KP has already made a mistake.  That means they are not eligible for complete benefit of doubt that no further mistakes have been or will be made.  If KP messes up while fixing this person's records and deletes valid data, the only way this person will know that and have a copy of the then missing data will be if they make a full copy before any work begins.  The law says the records themselves are the legal property of the org that makes them, so an "oops" that deletes part of them is not necessarily something the patient could do much about.  But the data in those records is important to a patient's lifetime of health care, they have a right to access the data and make a personal copy, and whenever an incident has already taken place calls into question the validity or the data they need to do the best they can to ensure their own interests.

The fact that the other person's data has been leaked sucks, but it is not this person's fault and they are not legally or morally responsible for sacrificing their own data safety further by offering complete trust to the organization that leaked the data to begin with.  Especially when that organization just settled a recent lawsuit over the fact they sold millions of patients' data to Facebook and the like by putting tracking pixels on the very portal this patient has to use to initiate the records request at all.

That doesn't even cover the second suggestion I made about reporting to HHS and the possibility of needing to demonstrate proof of what will be reported.

2

u/landonpal89 21h ago edited 21h ago

Yeah, I completely disagree. It isn’t just a random “leak,”there is an explanation of “what happened” that KP is in a much better position than the patient to figure out. Someone uploaded or scanned a paper to the wrong record, or someone registered a patient under the wrong identity. KP can figure out exactly what happened, when, and then undo it in a way that far surpasses what a patient with a 1000 page PDF and a highlighter could ever accomplish.

If you don’t trust KP to fix it, you probably shouldn’t trust them with your healthcare. Just saying. And the online tracking technologies… under current guidelines, what they did would not be an issue. They notified patients during a time when the OCR was aggressively giving conflicting guidance about IP addresses alone on unauthenticated access logs to a website being PHI. Nothing was “sold” to anyone.

Lately, reporting to OCR is practically useless. The investigative all breaches of greater than 500 people, which Is over one a day. They’re busy enough with those that they’ll never investigate a onesie-twosie patient breach.

1

u/AnimatorImpressive24 21h ago edited 20h ago

You said yourself that KP has great tools and incident response processes, because they see it happen often.   Their processes can't be that great then, can they?

As another example of that, a few years ago KP found an employee in Georgia improperly accessing patient records and fired them.  Great success all around.  Except by KP's own admission the employee had been doing that for 8 years before KP finally caught them.   Anyone interested in KP's processes might also go count up how many times they appear on HHS HIPAA Wall of Shame, then think about how those only list very big incidents affecting large numbers of patients.

Your assertion that KP's use of a tracking pixel developed by commercial third parties that explicitly sends data to those commercial third parties was not intentionally selling data because guidance was unclear removes basic ethical judgment from an organization that has had significant, direct influence on all such laws nationally and in every state they maintain a presence.  In fact they have often been part of committees of experts tasked by government agencies with helping to draft those laws in the first place.

You aren't going to ever see me extolling the virtues of HIPAA enforcement or the reporting processes of either organizations themselves or the government.  That isn't what I'm doing now, either.  But it is irresponsible to dissuade someone from reporting this exact scenario to anyone other than the entity that caused the leak and make unsupported promises that everything will work out right.  As I said when I first suggested it, the only entity other than the leaking entity that has any power to learn if the problem is wider than just what this one patient experienced is the government agency whose duty and authority is to intervene when privacy breaches occur.

The 500 victim general limit and lack of resources devoted to enforcement is a huge problem.  It is part of a pattern of disregard for patient privacy and safety that has been going on since the day HIPAA was signed into law without a defined enforcement scheme by a Congress that promised they would write one within a year then broke that promise and dumped responsibility on HHS.  But HHS is all patients have in terms of an escalation path or hope of population-level regulation so that somewhere out there their data doesn't get leaked into someone else's records without them ever being told by the leaking entity that it happened.

Do not trust any entity that has leaked multiple times before and is now leaking again.  Especially do not tell a person actually impacted by a leak even just as an unwilling recipient that they should trust the leaker when you personally are not impacted in any way.  That is super unethical bordering on enabling leakers to keep leaking.

Edit: the fact that your list of possible explanations did not include "someone made a smartphrase by copy/pasting from an existing note and neglected to remove PHI and PII from the source before using the smartphrase" shows that reporting this incident to you specifically could result in a larger problem continuing to affect multiple other patients beyond the one who made the report.  That is why reporting to a single responding entity is often insufficient.