Dedicated to providing the latest
HIPAA compliance news

Mississippi’s Magnolia Health Fires Employee for PHI Disclosure

Share this article on:

Magnolia Health, a health insurance company serving Mississippi’s Medicaid population, has announced it has fired an employee for inappropriately accessing the protected health information (PHI) of “numerous Magnolia Health members” and disclosing those data to a relative.

The disclosure of PHI was against company regulations and the now former employee has not received authorization from the company or patients to share their data. The disclosure happened on two occasions: October 28, 2015., and November 8, 2015. The data were emailed from the employee’s work email account to a personal account and email account of a relative.

Upon discovery of the privacy breaches the Centene Corporation subsidiary conducted an investigation which resulted in the termination of the employment contract of the employee in question. Written statements were obtained from the employee and the recipient of the PHI stating they had not disclosed the data to any other individuals. Magnolia Health also viewed the personal email accounts of both individuals to confirm that all copies of the data had been deleted.

The data emailed from the employee’s account included the names of health plan members, their addresses and telephone numbers, dates of birth, Medicaid ID numbers, and Social Security numbers. No reason was given as to why the data were emailed to the relative.

Magnolia Health has not disclosed how many individuals had their PHI compromised by the employee; however, the privacy breach was reported to the Mississippi Division of Medicaid. A breach report has not been added to the Department of Health and Human Services’ Office for Civil Rights breach portal. This suggests that the data breach affected fewer than 500 individuals. A substitute breach notice was posted on the Magnolia Health website on February 19, 2016.

All affected patients have been notified of the disclosure of their PHI and all have been offered a year of credit monitoring and identity theft protection services without charge.

Author: HIPAA Journal

HIPAA Journal provides the most comprehensive coverage of HIPAA news anywhere online, in addition to independent advice about HIPAA compliance and the best practices to adopt to avoid data breaches, HIPAA violations and regulatory fines.

Share This Post On