patient privacy violations

Patient privacy violations were highest at Veterans Affairs and CVS Health based on the number of federal citations, according to a new report.

In response, VA said the agency “takes veteran privacy and the privacy of medical or health records very seriously.” But despite its “very” serious approach to patient privacy, VA tied CVS for the most privacy complaints that resulted in corrective action plans or “technical assistance” from US Department of Health and Human Services (HHS) from 2011 to 2014.

How can we continue to believe VA when it continues to have problems in protecting veteran privacy? Why is this always an issue for the agency; is it because of the sheer number of patients or is there something more going on?


ProPublica received the information through a Freedom of Information Act request covering the years between 2011 to 2014; the latter was the most recent year data on patient privacy violations was available.

In addition to the above citations, the nonprofit journalism organization also found:

  • In 2014, HHS received more than 17,000 complaints, as well as tens of thousands of self-reported breaches of medical information.
  • Some providers inadvertently, or in some cases deliberately, shared patients’ medical information without their permission.
  • The top five categories of complaints in 2014 were impermissible uses and disclosures, safeguards, administrative safeguards, access and technical safeguards.

What do you want to bet VA beat out CVS in the “deliberately” sharing of patient data category?

Each year, VA says it “takes veteran privacy” very seriously. We are asked to trust the agency. Still, VA continues to receive these dubious citations each year.

Why is it still an issue?


Is it possible that VA does take privacy seriously on a corporate level but repeatedly fails to follow through with the mission by holding violators accountable?

My best guess is that these persistent privacy problems have more to do with lower level medical professionals not following the law while higher-level executives refuse to hold them accountable.

Maybe this makes it a two-fer kind of betrayal of the public trust and why VA continues to top the charts in patient privacy violations.


From Ben’s article, I quote: “[The VA said: “VA takes veteran privacy and the privacy of medical or health records very seriously.]” Anyone find it odd that the VA makes a point in it’s limited statement and words to differentiate “Medical or Health Records” in that spin? Is that not an oxymoronic spin and to what purpose? Is there a way they can for instance, reclassify a Vet’s Medical to “Health” to use some loophole to transmit VA Telemedicine Hack… Read more »
There is no privacy at the VA. They give your information to whoever they want!

I think you hit it right on the head Ben. I believe the violations are by those much lower, and although VA management may have policies in place, they give them lip service and refuse to hold anyone accountable. It reminds me of an earlier post I believe you had here some months ago. I read somewhere (maybe ProPublica) that the VA was patting themselves on the back for encouraging employees to voluntarily report violations in some official system they… Read more »
On another note…did anyone catch the Forbes article about VA art? The VA apologizes for pissing away millions in art, then rather than stopping it, they just set rules for buying it since they had none previously. Under the new rules, a hospital director can only spend up to $25000 on certain “art”, a VISN director has to approve anything between $25000 and $50000, and VACO has to approve anything over $50000. It’s from the new VHA Directive 1395, Appendix… Read more »
Dina Padilla
I wrote to the Federal Trade Comm about Kaiser Permanente getting caught using over 31,000 ex-employees, those that were fired, using their documents to get them to use kaiser as their new health care provider and the HHS stated that there was no problem. Mind you I didn’t send the complaint to HHS but to the FTC. It seems that when a filing a complaint to a specific dept, they transfer it to the (wrong) department WHICH THEN helps hide… Read more »
I was much better off on Medicaid, before I was forced to get Medicare, and VA. I cannot consciously go to the VA for anything other than prescriptions I have been given by outside Dr’s. I’m definitely in financial trouble because I don’t use VA, but I’m alive. I’m sure I wouldn’t be if I was forced to use the VA. All private and public insurance is going up, and that will hurt me. If I am no longer capable… Read more »
Ronald Nesler

No matter what outrageous breach of law, ethics or usage VA commits, they have one stock defense. To release a statement, saying that they take the issue seriously. A bunch of lying clowns, my cat has more integrity than VA.

Christine Zav
I was an employee of the VA and also a veteran. I retired with PTSD. The dentist I worked with went into my medical record (which was illegal) a Privacy Act Violation. He shared the information with his wife who confronted me about my meds. The Director and the Privacy Act Officer were totally aware of the entire situation and although they had a responsibility to take it further all they did was send me an apology letter. A Privacy… Read more »