3 ms·
Pretty much the same thing happened to me just a few weeks ago. I found out someone used my insurance info to pay for their emergency room visit. After much a
by matmann2001 10y ago
Pretty much the same thing happened to me just a few weeks ago. I found out someone used my insurance info to pay for their emergency room visit.
After much amateur sleuth-work, I came to find that the person had the exact same name and birth date, and the hospital had messed up the insurance lookup.
Of course, when I called the hospital to resolve the situation, and provided a copy of my license to prove my identity, they admitted they made a mistake.
And two weeks later, they used to the address from my license to send me the hospital bill.
- fencepost 10y agoPerhaps you need to look at this differently and address it with someone other than the billing department. "Two weeks later they used the address from my license to illegally send me someone else's PHI." If calling the hospital and asking to talk to someone "Because you sent me someone else's medical information" doesn't get their attention, ask them about their breach notification procedures. edit: phrasing
- matmann2001 10y agoI honestly don't think anyone that I'd be able to talk to on the phone there cares. Between the 4 or 5 people they passed me around to, I was given info about this other person that they had no right to give out. And that's the lesson here. Customer support representatives are so far removed from positions where they can actually be helpful, that all they are able to provide anymore is apathy and canned responses.
- fencepost 10y agoThat's why I phrased it as I did. I'm pretty sure that by sending his bills (presumably containing information on procedures performed, ICD10 detailed diagnosis codes, etc.) this could be considered a breach. Obviously it covers fewer than 500 individuals and the matching names is a complicating factor, but I believe that they're still required to report it to HHS within the first 2 months of 2018, and to notify the other person. Assuming that their training is worth anything at all, getting a supervisor and saying "I believe there's been a HIPAA violation and I need to know who to talk to" should get IMMEDIATE attention - it goes beyond application of a clue-by-four and should immediately get you connected to their Compliance Officer. That person should have all sorts of motivation to get things straightened out so it's not an ongoing breach with further disclosures post-notification. The other kicker is that I believe the rules changed recently such that if an individual reports a breach and it results in fines, that individual may now receive part of the penalty amount (caveat: I didn't find a citation for this, just have heard it discussed somewhere). My guess is that in your case with a matching name it's unlikely that there'd be anything like that, but just the prospect of the headaches involved should motivate people to resolve the situation.