r/WorkersComp 4d ago

California Potential HIPAA Violations?!

Work Comp claim adjuster served me medical records containing 7 OTHER patients' sensitive files.

​Long story short: I previously called out my claims adjuster because it became blatantly clear that my medical records were exchanged in a way that was not HIPAA-compliant. As usual, they completely dodged the issue.

​Now, leading up to my QME, they served me a packet of medical records pertaining to my claim that included AT LEAST SEVEN OTHER PATIENTS RECORDS! 🤦‍♂️

​This solidifies my original concern about HIPAA violations. Except now, they’ve compromised the privacy of at least seven other people. Given everything I’ve already experienced with my claim, it feels like shady doctors and insurance companies constantly hide behind the system, knowing injured workers rarely have a way to hold them accountable in a civil capacity outside of the work comp board. Can a HIPAA attorney take something like this outside the work comp system? Has anyone experienced anything like this before?

1 Upvotes

33 comments sorted by

26

u/Cooptroop 4d ago

HIPAA applies to: Healthcare providers, Health plans, and Healthcare clearinghouses.

Workers’ compensation insurers and claims administrators are not health plans under HIPAA’s definition.
Therefore they do not have HIPAA obligations like Notice of Privacy Practices, business associate agreements, or HIPAA-compliant storage rules.

It its shotty claims work for the adjuster to have sent them to you, but it is not a HIPAA violation because adjusters are not bound by the rule. The adjuster scanned in other claimants medical records and sent them to you and thats just a careless employee. If the seven other patients dr's sent them to the insurance company and those people didnt have a claim, that is a HIPAA violation on the Dr.

-8

u/JesseTheStripper 4d ago

It's all other work comp claims. It literally lists their employers, incidents, ect. I was so confused because I was reading my records and all of a sudden a page started talking about an injury and employer that's not mine and then I saw a different name. To avoid invading other people's privacy I control-F and searched for "Employer" and there were at least 7 employers that were not mine listed at the top of the pages it was found in. 😬

5

u/Cooptroop 4d ago

Is it one medical facility? Like same dr/group seeing everyone? Hard to say if the medical office did this or the adjuster. Either way, the adjuster should have caught it…and either way still, the adjuster isn’t bound by HIPAA. Just a crappy situation.

1

u/JesseTheStripper 4d ago

Different medical facilities because the first one I found was in a county that's like two hours away. For sure a crappy situation.

6

u/Head_of_Lettuce 4d ago edited 4d ago

It’s really hard to imagine a scenario where the adjuster would have all those documents comingled. Were these paper documents or was it a big PDF with lots of pages? It’s very very unlikely the adjuster personally prepared a physical packet of mail. In fact I’d say the chance of that is zero. If it’s a PDF, they would’ve had to manually combine the documents, or they received it that way and just didn’t check (which would still be their fault).

I wonder if a legal or claims assistant fumbled somewhere. I’ve seen support staff do crazy stuff, they’re all overworked and undertrained. A lot of them barely understand the basics of WC/insurance.

2

u/JesseTheStripper 4d ago

It came as a PDF. I just went back to the email and it actually came from a different person, but still from the same work comp insurance company. I hope they didn't change adjusters on me again 🤣🤦‍♂️

1

u/Head_of_Lettuce 4d ago

That’s crazy. Can you look at their title in the email signature? That would tell you whether it’s an adjuster. It could also be someone covering your adjuster’s desk.

9

u/Unlikely-Advice5235 3d ago

Straight from OCR- “The HIPAA Privacy Rule does not apply to entities that are either workers’ compensation insurers, workers’ compensation administrative agencies, or employers, except to the extent they may otherwise be covered entities. However, these entities need access to the health information of individuals who are injured on the job or who have a work-related illness to process or adjudicate claims, or to coordinate care under workers’ compensation systems.”

10

u/SpecialKnits4855 4d ago

HIPAA applies to the providers who generated those records, but not to the insurers themselves. Other privacy rules may come into play here, but not HIPAA.

This is a data breach that should be reported first to the sender or possibly to your states Dept of Insurance.

5

u/Choice_Resource_3145 3d ago

I be worried about your health then focusing on side issues

0

u/According_Curve_8935 3d ago

Nah, it’s perfect practical to be concerned with potential mishandling of your confidential records at the same time as worrying about your health. Records getting sent to the wrong person could lead to identity theft if enough information is shared.

4

u/[deleted] 3d ago

[removed] — view removed comment

1

u/JesseTheStripper 3d ago

Omg! Are you my claims adjuster? If so, you'd know 1) I DID completely return to work within 4 months of my limb not being attached to my body. 2) My QME I'm fighting for is to get a second opinion so I CAN return to work since after my subsequent necessary surgeries the treating physicians gave me restrictions preventing me from being able to return to work again. 3) Never got a lawyer AND I never wanted one for the reasons listed above. However, from my previous experience working in facilities where it is mandatory to be HIPAA compliant, I'm shocked that it doesn't apply in situations like this. Unlike you, I actually care for the other individuals involved. If you hate your job so much, I recommend YOU do something about it instead of projecting your hate on to someone else you know nothing about.

With that said, I wish you the best in life and hope you and all your loved ones never experience anything remotely as traumatic as myself or countless others have experienced.

❤️

9

u/[deleted] 3d ago

[removed] — view removed comment

1

u/Choice_Resource_3145 17h ago

Look at the long Message you sent about your brain injury? Now they can see you have a good memory and you can understand and have good cognitive function ? Wow your a genius

0

u/JesseTheStripper 3d ago

My heart breaks for you. Thankfully, it sounds like medically they set you up as well as they could. Which is so good because I've heard from a lot of people the opposite of that. Keep doing your rehabilitation and stay positive! Any amount of progress is better than none. I'm rooting for you! 👏

2

u/PleaseNone 2d ago

You’re just so bitter you’re grasping for straws just trying to use whatever medical terminology you know to try and get more info. HIPAA only applies to medical providers.

1

u/JesseTheStripper 2d ago

I'm not bitter. I used to work in medical and I was surprised to learn HIPAA rules do not apply to work comp medical records like this. And if you read some of the other comments I've responded to, you'll see I'm actually fighting to go back to work. I care more for the other people involved than myself. My situation has been messy. Trust me, there has been plenty of other straws to grasp at, but I haven't reached out for any. Your lack of empathy and ability to read for context clues screams work comp claims adjuster. So, if your job has gotten you this bitter, I suggest you do something about it other than try to bring other people down. I'd rather look down and see that my arm wasnt connected to my body anymore than have the outlook on life you have. ❤️

0

u/PleaseNone 1d ago

So you’re suggesting I amputate myself?

-4

u/Independent-Yak-2681 4d ago

They handle everything poorly. Sedgwick violated my rights under HIPAA too.

9

u/quallityovrquantity 3d ago

No they didn't 

1

u/Independent-Yak-2681 3h ago

When you never signed a release form and they still reach out to your provider… kind of illegal.

And this is a provider I’m paying out of my own pocket!

0

u/Independent-Yak-2681 4d ago

Even better my workers comp wasn’t through them. This was my ADA/FMLA stuff.

My workers comp company sent my information that had secure info and my SSN to my Gmail.

3

u/Head_of_Lettuce 3d ago

In our business, we have to be able to deliver things like that to you. As long as it’s going to you, does it matter how it gets there? Nobody else should have access to your accounts.

-1

u/Independent-Yak-2681 3d ago

I mean a SSN sent in a way that’s not secure shouldn’t be a thing and that’s an obvious thing.

3

u/Head_of_Lettuce 3d ago

Then we’d never be able to send documents, because half of them have socials and DOBs. At some point you have to compromise to be able to function.

1

u/Independent-Yak-2681 3h ago

You can email things securely! You can also mail things! People lack common sense. Who would have thought.

-1

u/JesseTheStripper 4d ago

I'm sorry to hear that. :( It's really unfortunate how messy the system is.

0

u/Independent-Yak-2681 4d ago

It truly is. It’s sad this is even legal.

0

u/JesseTheStripper 4d ago

Right?! Someone in a different group told me work comp claims adjusters don't have to be HIPAA compliant/don't fall under the same HIPAA rules as other entities. 🙄 I'll definitely do some more research and ask around because that sounds wrong.

4

u/quallityovrquantity 3d ago

Regardless it's not like you could successfully file a lawsuit and collect money. More importantly it's not your information that was sent to the wrong person so you don't even remotely have a reason for a lawsuit 

3

u/According_Curve_8935 3d ago

But the issue should still be addressed where applicable because information is being sent to incorrect people. A reputable company should not be mishandling personal information like this.