On March 15, 2022, the information below from my EMR pertaining to my hospitalization from March 9, 2022, to March 11, 2022, was accessed and sent via email by someone who was non-medical staff. I received a data breach letter dated May 5, 2022, which concerned me greatly. When I alerted Francis before I knew it was him, he skipped our visit that week.
What was accessed?
My Name
Medical Record Number
Address
Date of Birth
Sex
Last Four Digits of SSN
Visit Dates
Procedures Performed
Results
Symptoms
Diagnosis
Medication Prescribed
Telephone Encounter Documentation
Email Communications
After I was released from the hospital, Francis said something very odd to me about how much trouble he had accessing my records, which he was never authorized to do in the first place. I just looked at him like, “What???” and he immediately changed the subject. This occurred in March 2022 when he came to see me where I was parked in my vehicle as a homeless person. Did he think I would never find out? I did.
Needless to say, this was very invasive and illegal. Francis was my outreach worker from Opportunity, Inc., as well as an employee of Kaiser Permanente, and I became very triggered by his actions.
The data breach letter stated that it involved non-medical staff. Then Francis told my friend Alex that it was him who did it, after I made a really big deal out of it at the shelter where I had just been placed. Francis also pretended to be me on the Social Security Administration (SSA) website, which they alerted me to on June 15, 2022 by email. Did he think I wouldn’t find out? I did. When I brought it up, he said the email was from him. However the email was from no-reply@login.gov. So, Francis lied, and as far as know, was never held accountable by Opportunity, Inc. He was actually promoted.