Common use of Covered Conduct Clause in Contracts

Covered Conduct. On January 6, 2012, HHS notified SRMC of its initiation of a compliance review of its facility to determine whether there was a failure to comply with the requirements of the Privacy Rule. HHS’s compliance review was prompted by an article in the Los Angeles Times published on January 4, 2012. The article indicated that two of SRMC’s senior leaders met with the media to discuss the medical services provided to a patient (the Affected Party) without a valid written authorization. HHS’s investigation indicated that the following conduct occurred (“Covered Conduct”): a) From December 13 – 20, 2011, SRMC failed to safeguard the Affected Party’s PHI from any impermissible intentional or unintentional disclosure on multiple occasions as described below. This failure was evidenced by the following facts: i) On December 13, 2011, SRMC sent a letter, through its parent company, to California Watch, responding to a story concerning Medicare fraud. The letter described the Affected Party’s medical treatment and provided specifics about her lab results. SRMC did not have a written authorization from the Affected Party to disclose this information to this news outlet. ii) On December 16, 2011, two of SRMC’s senior leaders met with The Record Searchlight’s editor to discuss the Affected Party’s medical record in detail. SRMC did not have a written authorization from the Affected Party to disclose this information to this newspaper. iii) On December 20, 2011, SRMC sent a letter to The Los Angeles Times, which contained detailed information about the treatment the Affected Party received. SRMC did not have a written authorization from the Affected Party to disclose this information to this newspaper. b) SRMC impermissibly used the affected party’s PHI. This failure was evidenced by the following facts: i) On December 20, 2011, SRMC sent an email to its entire workforce and medical staff, approximately 785-900 individuals, describing, in detail, the Affected Party’s medical condition, diagnosis and treatment. SRMC did not have a written authorization from the Affected Party to share this information with SRMC’s entire workforce and medical staff. c) SRMC has failed to sanction its workforce members pursuant to its internal sanctions policy which requires that it sanction employees for “violations of HIPAA”.

Appears in 2 contracts

Sources: Resolution Agreement, Resolution Agreement