F0583 F583: Keep residents' personal and medical records private and confidential.
D

Unauthorized Disclosure of Resident PHI via Email

Monrovia Gardens Healthcare CenterMonrovia, California Survey Completed on 03-27-2025

Summary

A deficiency occurred when the Social Services Director (SSD) sent an email containing a resident's Face Sheet (Admission Record) and information regarding podiatry care needs to an unauthorized recipient, specifically another resident's family member. The email included protected health information (PHI) such as the resident's Medicaid, Medicare, and insurance policy numbers, home address, care providers, emergency contact, and financial representative. The SSD stated that the email was sent by mistake, confusing the intended recipient, a medical provider with the same first name as the family member who received the email. The resident whose information was disclosed had a history of anemia, chronic pain, and gout, and was noted to have severely impaired cognition, requiring substantial to maximal assistance with activities of daily living. The resident was able to make needs known but could not make medical decisions. The SSD recognized the error and attempted to recall the email but did not report the incident to facility leadership or follow the facility's policy for handling breaches of PHI. Interviews with the Administrator and Director of Nursing revealed that the facility's protocol required immediate reporting of any PHI breach to leadership, investigation of the incident, and notification of the resident or responsible party. The facility's policy also specified that access to resident records should be limited to authorized staff and business associates, which was not followed in this instance.

Plan Of Correction

How corrective actions will be accomplished for those residents found to have been affected by the deficient practice: Resident 8 was informed of the breach on March 26, 2025, and was assured that the facility would take all appropriate steps to mitigate any potential negative consequences resulting from the incident. How the facility will identify other residents having the potential to be affected by the same deficient practice and what corrective action will be taken: All residents had the potential to be affected by this deficient practice. Beginning on March 27, 2025, the Social Services Director conducted outreach to residents within the facility to identify any additional potential breaches and to ensure there were no further incidents or concerns related to the confidentiality of Protected Health Information (PHI). No additional findings were identified as a result of this review. What measures will be put into place or what systemic changes will the facility make to ensure that the deficient practice does not recur: From March 27 to March 28, 2025, licensed nurses and department supervisors participated in an in-service training conducted by the Administrator or designee. The training focused on the protection of residents' rights to privacy and the confidentiality of Protected Health Information (PHI), in accordance with HIPAA regulations. On March 27, 2025, the Administrator conducted a one-on-one training with the Social Services Director, emphasizing the importance of secure communication practices and the protection of residents' rights to privacy and the confidentiality of Protected Health Information (PHI), in compliance with HIPAA regulations. The Social Services Director will adhere to safe communication practices and will promptly report any potential breaches of confidentiality to the Administrator for further review and appropriate action. How the facility plans to monitor its performance to make sure that solutions are sustained: The ADMIN/designee will provide any negative findings to QAPI committee monthly x 3 months for further monitoring and action planning as indicated or until the QAA committee determines compliance. Date of Compliance: April 1st, 2025

Penalty

No penalty information released
tooltip icon
The penalty, as released by CMS, applies to the entire inspection this citation is part of, covering all citations and f-tags issued, not just this specific f-tag. For the complete original report, please refer to the 'Details' section.

Resources

Below are regulatory guidelines relevant to this citation:

See other F0583 citations
Electronic Medical Records Left Visible on Unattended Computers
D
F0583 F583: Keep residents' personal and medical records private and confidential.
Short Summary

Electronic Medical Records Left Visible on Unattended Computers: Two residents' EMRs were left open and visible on unattended computers during wound care and med pass. One resident had HTN, DM, and malnutrition with moderate cognitive impairment, and another resident had acute respiratory failure with hypoxia, HTN, DM2, and Afib with intact cognition. Staff confirmed the screens were left open and available for public view.

No penalty information released
tooltip icon
The penalty, as released by CMS, applies to the entire inspection this citation is part of, covering all citations and f-tags issued, not just this specific f-tag. For the complete original report, please refer to the 'Details' section.
Failure to Protect Confidential Resident Information
D
F0583 F583: Keep residents' personal and medical records private and confidential.
Short Summary

A resident's confidential medical information was left visible on the East med cart computer screen at the nurses station when the cart was unattended. An RN confirmed the observation and acknowledged that resident personal and clinical information was exposed to anyone passing by.

No penalty information released
tooltip icon
The penalty, as released by CMS, applies to the entire inspection this citation is part of, covering all citations and f-tags issued, not just this specific f-tag. For the complete original report, please refer to the 'Details' section.
Failure to Protect Confidential Medical Records
F
F0583 F583: Keep residents' personal and medical records private and confidential.
Short Summary

A facility failed to keep residents’ personal and medical records secure and confidential. Medical record review showed hospice notes were entered directly into the EMR for three residents, and the regional clinical director stated the hospice previously used was given full access to the EMR for all residents. The Resident Rights policy stated residents have a right to secure and confidential personal and medical records.

No penalty information released
tooltip icon
The penalty, as released by CMS, applies to the entire inspection this citation is part of, covering all citations and f-tags issued, not just this specific f-tag. For the complete original report, please refer to the 'Details' section.
Failure to Deliver Resident Mail Promptly
E
F0583 F583: Keep residents' personal and medical records private and confidential.
Short Summary

Failure to Deliver Resident Mail Promptly: The facility failed to ensure residents could send and receive mail and other materials in a timely manner. In a group interview, multiple residents stated they never received mail or that mail was not distributed on Saturdays because the AD did not work weekends. The AD said she passed mail Monday through Friday and was unsure who handled Saturday delivery, while the Administrator said weekend nursing staff were expected to pass mail. The facility policy required mail delivery within 24 hours of receipt.

No penalty information released
tooltip icon
The penalty, as released by CMS, applies to the entire inspection this citation is part of, covering all citations and f-tags issued, not just this specific f-tag. For the complete original report, please refer to the 'Details' section.
Failure to Provide Privacy During Incontinent Care
D
F0583 F583: Keep residents' personal and medical records private and confidential.
Short Summary

A cognitively intact female resident with Guillain-Barre Syndrome, depression, muscle weakness, and dependence on staff for toileting received incontinent care from two CNAs while her roommate was present in the room, and the privacy curtain was not pulled at any time. The resident’s care plan documented a self-care deficit and need for assisted incontinent care, and facility policies on perineal care and resident rights required staff to provide privacy, including use of doors, curtains, and blinds. In post-incident interviews, both CNAs acknowledged that privacy should have been provided during the care and recognized that doing so is part of respecting resident rights and dignity, while the DON and Administrator confirmed their expectation that staff follow these privacy practices.

No penalty information released
tooltip icon
The penalty, as released by CMS, applies to the entire inspection this citation is part of, covering all citations and f-tags issued, not just this specific f-tag. For the complete original report, please refer to the 'Details' section.
Failure to Protect Resident Privacy During Glucose Monitoring and Insulin Administration
D
F0583 F583: Keep residents' personal and medical records private and confidential.
Short Summary

Two cognitively intact male residents with diabetes, one with additional psychiatric diagnoses, received blood glucose checks and, for one resident, an insulin injection in an open area near the nurse’s station rather than in a private setting, exposing their medical treatment to others. Facility leadership, including the DON and Administrator, acknowledged that facility policy and practice required such medical treatments to be performed in residents’ rooms to protect privacy and confidentiality of personal and medical records, and that providing these services in public areas was inconsistent with resident rights and privacy standards.

No penalty information released
tooltip icon
The penalty, as released by CMS, applies to the entire inspection this citation is part of, covering all citations and f-tags issued, not just this specific f-tag. For the complete original report, please refer to the 'Details' section.
Citation search

Search every citation & Plan of Correction

Go to search
Citation watch

Track new serious citations across California

Get a heads-up on the newest immediate-jeopardy (J–L) citations in California — where surveyors are focused right now.

Free · about one email a month

Trusted data from CMS and state health departments

Every citation, penalty and Plan of Correction is sourced from public CMS records (latest release August 26, 2026) and official state health department websites — never guesswork.

In your survey window? See what surveyors are citing.

The Survey-Prep Report maps your facility's risk from 12 months of CMS and state citation data — what's being cited around you and what to check first. $129 one-time.

Get the Survey-Prep Report
An unhandled error has occurred. Reload 🗙

Connection lost — reconnecting… We couldn't reconnect automatically. Please reload the page to continue.