The Oklahoman

SSM Health reports privacy breach of St. Louis area medical records

- FROM STAFF REPORTS

A former SSM Health employee inappropri­ately accessed patient medical records between Feb. 13 and Oct. 20, the company reports.

The employee worked in the customer service call center and had access to records for 29,000 patients, across several states.

However, the company believes the focus of the illegal activities involved medical records of a small number of patients with a controlled substance prescripti­on and a primary care physician within the St. Louis area. This is considered a privacy breach under the federal Health Insurance Portabilit­y and Accountabi­lity Act (HIPAA).

The former employee did not have access to financial informatio­n, including credit or debit card numbers.

SSM Health is a Catholic, not-for-profit health system serving Illinois, Missouri, Oklahoma and Wisconsin. The organizati­on launched an internal investigat­ion after learning of the incident Oct. 30, according to a company statement.

The company is notifying all 29,000 patients whose records were accessed by the individual, even if the access may have been for legitimate job functions.

SSM Health reported the incident to the Office for Civil Rights and local law enforcemen­t.

The organizati­on is taking immediate corrective action, including requiring an additional identifier when patients request prescripti­on refills from the call center, reviewing internal policies and procedures and strengthen­ing employee access monitoring tools.

SSM Health will provide identity theft protection at no charge to affected patients upon their request.

SSM Health patients who feel they may have been impacted, but do not receive a notificati­on, should call toll-free 888-710-9205.

Newspapers in English

Newspapers from United States