A case in the waiting room led to the disclosure of PHI within a closed entity. According to the case data, a staff member discussed HIV testing procedures with a patient in the waiting room, disclosing PHI to several other individuals within the waiting room.
Moreover, the computers that displayed patient information were easily visible to other patients.
To rectify the situation, the OCR required the provider to develop policies regarding physical safeguards related to the communication of PHI.
As a result, the entity trained its staff according to the newly-developed policy that involved privately communicating with patients and re-positioning the commuting systems containing patient information.