F0583 F583: Keep residents' personal and medical records private and confidential.
D

Unauthorized Disclosure of Resident PHI to Outside Contractor

The Laurels Of GahannaColumbus, Ohio Survey Completed on 04-15-2026

Summary

The facility failed to protect a resident’s right to privacy and confidentiality of personal and medical records when it disclosed protected health information (PHI) to an outside contractor without proper authorization. The resident, admitted with diagnoses including cognitive communication deficit, history of transient ischemic attack and cerebral infarction, and end stage renal disease, had a BIMS score of 11 on a quarterly MDS, indicating moderate cognitive impairment. Record review showed the resident had a healthcare POA appointed on 08/19/25 and a financial POA appointed on 09/21/25, both naming the same individual, with the financial POA effective immediately. Despite this, the facility could not provide documentation that the POA had consented to share the resident’s information with Contract Company #500. The Float Business Office Manager confirmed that a face sheet for this resident was provided to Contract Company #500 on 03/12/26 without the POA’s consent to release HIPAA-related information to an outside provider. The POA stated she did not authorize the sharing of the face sheet and reported that the contractor contacted the resident’s bank and insurance company without her consent. The resident reported significant memory issues, inconsistent recall, and missing details, and stated she had communicated these limitations to the contractor multiple times. The resident was unaware that the contractor had her face sheet prior to their meeting and reported feeling unhappy and uneasy upon learning that her personal information had been shared without her knowledge. The contractor representative confirmed that his company received the resident’s face sheet from the facility. Review of the facility’s HIPAA policy showed that the facility may not disclose an individual’s PHI without written authorization.

Penalty

No penalty information released
tooltip icon
The penalty, as released by CMS, applies to the entire inspection this citation is part of, covering all citations and f-tags issued, not just this specific f-tag. For the complete original report, please refer to the 'Details' section.

Resources

Below are regulatory guidelines relevant to this citation:

See other F0583 citations in Ohio
Unsecured Electronic Charting System During Med Pass
E
F0583 F583: Keep residents' personal and medical records private and confidential.
Short Summary

Surveyors found that during a morning med pass on one hall, RNs repeatedly left a medication cart laptop open with the electronic charting system visible and accessible while walking away to administer meds in resident rooms. A staff member confirmed the laptop remained open and unsecured even as a resident ambulated nearby. In interviews, an RN acknowledged not following the expected practice of minimizing the charting system and closing the laptop screen, and facility leadership confirmed there was no formal written policy on securing laptops when staff left the med cart, despite an expectation that screens be closed to prevent visibility.

No penalty information released
tooltip icon
The penalty, as released by CMS, applies to the entire inspection this citation is part of, covering all citations and f-tags issued, not just this specific f-tag. For the complete original report, please refer to the 'Details' section.
Failure to Ensure Privacy During Incontinence Care
D
F0583 F583: Keep residents' personal and medical records private and confidential.
Short Summary

A cognitively intact, fully dependent and always incontinent resident received incontinence care from a CNA in a shared room without the privacy curtain being drawn, despite the roommate being present. During the care, the resident’s genital area and buttocks were exposed while the CNA removed the adult brief and cleaned the resident. The resident later reported that staff sometimes forget to pull the curtain and that this exposure sometimes bothers him, and the CNA acknowledged not using the privacy curtain, contrary to facility policy on resident privacy during personal care.

No penalty information released
tooltip icon
The penalty, as released by CMS, applies to the entire inspection this citation is part of, covering all citations and f-tags issued, not just this specific f-tag. For the complete original report, please refer to the 'Details' section.
Unauthorized Cellphone Recording of Resident Without Consent
D
F0583 F583: Keep residents' personal and medical records private and confidential.
Short Summary

A cognitively intact resident with Huntington’s disease and other conditions was participating in chair exercises when a CNA used a personal cellphone to record the resident lifting her leg above her head, without any signed photo release or consent from the resident’s POA. Two other CNAs watched the event and did not report it. Other staff later observed the CNAs laughing and viewing the image on the phone. Review of incident reports, staff statements, and the facility’s social media policy confirmed that the recording was taken in the work area using a personal device and that facility policy prohibits taking or sharing resident photos or videos without prior written permission.

No penalty information released
tooltip icon
The penalty, as released by CMS, applies to the entire inspection this citation is part of, covering all citations and f-tags issued, not just this specific f-tag. For the complete original report, please refer to the 'Details' section.
Privacy Breach When Wrong Discharge Medications and Instructions Given to Another Resident
D
F0583 F583: Keep residents' personal and medical records private and confidential.
Short Summary

A resident who was cognitively intact and required supervision with ADLs was discharged, and an LPN mistakenly sent that resident’s representative home with another resident’s medications and written discharge instructions, which included detailed information on multiple prescribed drugs for serious conditions such as cerebral infarction, seizures, and sepsis. The error was discovered at shift change when the night nurse could not locate the second resident’s medications in the cart. The administrator and DON confirmed that the wrong medications and paperwork had been provided, and the discharging resident’s representative later reported to police that they had received another resident’s private health information, although none of the incorrect medications were taken.

No penalty information released
tooltip icon
The penalty, as released by CMS, applies to the entire inspection this citation is part of, covering all citations and f-tags issued, not just this specific f-tag. For the complete original report, please refer to the 'Details' section.
Failure to Protect Resident PHI During Medication Administration
E
F0583 F583: Keep residents' personal and medical records private and confidential.
Short Summary

Surveyors found that during medication administration, two RNs repeatedly left an electronic medical record screen open and visible on the med cart while entering resident rooms, exposing protected health information (PHI). For multiple residents with complex conditions such as diabetes, CHF, dementia, cerebral palsy, acute kidney failure, depression, and urinary issues, the EMR displayed names, room numbers, diagnoses, and medications and was not locked or secured. Both RNs confirmed in interviews that they did not lock the computer screens before leaving the cart, resulting in PHI being viewable to anyone passing by.

No penalty information released
tooltip icon
The penalty, as released by CMS, applies to the entire inspection this citation is part of, covering all citations and f-tags issued, not just this specific f-tag. For the complete original report, please refer to the 'Details' section.
Unattended Laptop Exposed Resident PHI at Nurses’ Station
D
F0583 F583: Keep residents' personal and medical records private and confidential.
Short Summary

An unattended medication cart laptop at the nurses’ station was left open to a cognitively intact resident’s electronic record, displaying PHI including the resident’s photo, name, gender, room number, date of birth, code status, allergies, and recent vital signs. The cart and laptop were unattended in a common area, allowing anyone passing by to view the information. An LPN confirmed the laptop was left open with visible PHI, despite a facility policy assigning staff responsibility to prevent unauthorized disclosure of PHI.

No penalty information released
tooltip icon
The penalty, as released by CMS, applies to the entire inspection this citation is part of, covering all citations and f-tags issued, not just this specific f-tag. For the complete original report, please refer to the 'Details' section.

99.5% of Ohio facilities received at least one citation during their inspection in the last 12 months.Will yours be survey-ready?

Surveyors issued 64 serious citations across Ohio in the last 12 months. See exactly what they're citing.

Get ready for your next survey

See what surveyors are citing in Ohio and spot your risk areas before they do.

Monthly Citation Reports

Have you been cited for this tag?

Save hours drafting a compliant Plan of Correction — AI built on real approved POCs.

Plan of Correction Writer

Trusted data from CMS and state health departments

Every citation, penalty and Plan of Correction is sourced from public CMS records (latest release June 24, 2026) and official state health department websites — never guesswork.

Trusted by long-term care providers and associations.

Allegria Senior Living logo
FHCA logo
WeCare Centers logo
Care Rehab logo
An unhandled error has occurred. Reload 🗙