Unattended Unlocked Laptop Exposes Resident PHI in Hallway
Summary
The deficiency involves the facility’s failure to protect residents’ personal privacy and the confidentiality of their medical records when an LVN left a laptop unlocked and unattended on a medication cart in a resident care hallway. On the specified date and time, a state surveyor observed a laptop on top of the medication cart between two occupied resident rooms on the 100 Hall. The laptop screen was on, unlocked, and displaying residents’ medication information that needed to be passed. The cart and laptop were unattended, and the laptop was positioned facing the hallway, making the information potentially visible to anyone walking by. During the observation period, two staff members and two residents walked past the unattended, unlocked laptop on the 100 Hall. The LVN later identified the laptop as hers and stated she had been using a hallway outlet to charge it while assisting a resident in their room. She believed she had locked the laptop before leaving it but acknowledged that, at the time of the surveyor’s observation, it was unlocked on the medication cart. The LVN reported she had been employed at the facility for 29 years and had received multiple in-service trainings on HIPAA, PHI, and protecting patient information, and that she normally locked laptops, computers, and medication carts when not in use. She also stated she was unaware that the surveyor had previously observed the same laptop unlocked and unattended earlier that morning. A CNA assigned to the same hall and shift reported she walked past the laptop on the medication cart but did not notice it was unlocked and did not know which staff member had last used it. She stated that such a laptop would contain patient records, including confidential medical information that should not be seen by unauthorized individuals, and that if she noticed an unlocked device she would notify the charge nurse. The DON, when interviewed, stated she was unaware of the incident but affirmed that computers and laptops should always be locked when unattended and that all employees were expected to maintain privacy and confidentiality of patient information. Record review showed that, for the period reviewed, there were no in-service trainings on residents’ privacy, and the facility lacked a specific policy on HIPAA, PHI, or safeguarding electronic records. Existing written policies on resident rights and medical record content did not address HIPAA, PHI, or electronic record safeguards, despite the facility’s practice of following HIPAA guidelines.
Penalty
Resources
Below are regulatory guidelines relevant to this citation:
Trusted data from CMS and state health departments
Every citation, penalty and Plan of Correction is sourced from public CMS records (latest release August 26, 2026) and official state health department websites — never guesswork.
In your survey window? See what surveyors are citing.
The Survey-Prep Report maps your facility's risk from 12 months of CMS and state citation data — what's being cited around you and what to check first. $129 one-time.