25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Montefiore Medical Center and Bethesda Hospital Fire Employees for HIPAA Breaches

Baptist Health’s Bethesda Hospital in Boynton Beach, FL has fired an employee for impermissibly accessing a patient’s protected health information and altering a home health order which was used to provide a patient with home care services.

The HIPAA breach was identified on December 1, 2020, prompting an internal investigation. The employee has now been terminated and the incident reported to law enforcement.

The investigation revealed other patient records may also have been accessed by the former employee between June 1, 2019 and December 2, 2020. The types of information potentially viewed included names, dates of birth, addresses, health insurance information, Social Security numbers, and clinical documentation.

All affected individuals have been notified and offered complimentary identity theft protection and credit monitoring services and Baptist Health is exploring ways to further safeguard patients’ protected health information and prevent similar breaches in the future.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The incident has yet to be listed on the HHS’ Office for Civil Rights’ website so it is currently unclear how many patients have been affected.

Montefiore Medical Center Fires Employee for Unauthorized Medical Record Access

Montefiore Medical Center in New York has discovered an employee accessed the protected health information of patients without authorization over a period of 5 months in 2020. Upon discovery of the unauthorized access, Montefiore immediately deactivated the employee’s access to the electronic medical record system and an investigation was launched to determine the extent of the HIPAA violations.

After a thorough investigation, the employee was terminated and the matter was reported to law enforcement for possible criminal prosecution. The types of information viewed by the former employee varied from patient to patient and may have included first and last names, addresses, dates of birth, medical record numbers, clinical information such as test results, diagnoses, and visit histories and the last four digits of Social Security numbers.

No reason was provided as to why the information was accessed, but no evidence was found to indicate patient information has been used for identity theft or fraud. All affected patients have now been notified and offered complimentary identity theft protection services.

This is the second incident involving improper medical record access to be announced by Montefiore Medical Center in the past 5 months. In September 2020, the medical center announced a former employee had stolen the PHI of approximately 4,000 patients between January 2018 and July 2020.

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist