PogoWasRight.org

Menu
  • About
  • Privacy
Menu

Attorney General Todd Rokita holds IU Health accountable for patient privacy and HIPAA violations

Posted on September 17, 2023 by pogowasright.org

Attorney General Todd Rokita filed a lawsuit on behalf of the people of Indiana against IU Health and IU Healthcare Associates for their failure to properly report, review, and enforce HIPAA and Indiana law violations.

“We will continue to uphold and protect Hoosier patients’ medical privacy,” Attorney General Rokita said. “Trust is the foundation of the patient-doctor relationship. Without trust, we don’t have reliable, honest healthcare.”

This issue was first brought to the office’s attention in 2022 when a 10-year-old rape victim and her mother went to an IU hospital for an abortion, as a result of the rape and abuse the child endured.

After the abortion, while the mother and daughter were still at the hospital for recovery and observation, they were greeted with a front-page news story in the Indianapolis Star, which described the 10-year-old’s case in great detail. This article went public, and the story became worldwide household news after the doctor spoke to a reporter at a political rally.

The 10-year-old’s treatment was a very private and sensitive matter, as was the rape and abuse she suffered that resulted in her pregnancy. Neither the little girl nor her mother gave the doctor authorization to speak to the media about their case.

Rather than protecting the patient, IU Health chose to protect the doctor, and itself.

On July 15, 2022, hospital administrators emailed statements to multiple media outlets informing them that they had conducted a review and “found the doctor in compliance with privacy laws.”

On May 25, 2023, the Indiana Medical Licensing Board conducted a hearing and determined that the doctor violated HIPAA by improperly disclosing patient information and for improperly de-identifying patient information, and the doctor violated the Indiana patient confidentiality rule by failing to get patient permission prior to disclosing any information.

The following day, IU Health issued a public statement in which it disagreed with the Medical Licensing Board’s determination once again claiming the doctor did not violate privacy laws.

By publicly contradicting the Medical Licensing Board and contending the doctor’s actions were “in compliance with privacy laws,” IU Health has caused confusion among its 36,000-member workforce regarding what conduct is permitted not only under HIPAA privacy laws and the Indiana Patient Confidentiality rule, and as a result, as Indiana’s largest health network, they created an environment that threatens the privacy of its Indiana patients.

Subsequent to the Medical License Board hearing, the office discovered numerous instances where IU Health has sanctioned non-physician employees with termination for far less egregious patient privacy violations but has failed to implement or enforce similar privacy policies or sanctions for its physicians.

“Doctors and all health care professionals should be able to rely on their employers and patients should be able to trust their doctors,” Attorney General Rokita said. “When a hospital or other healthcare provider makes your private medical information public, that trust is decimated. As a result, the quality, delivery, and sustainability of our healthcare is significantly weakened.”

The lawsuit consists of the following seven counts against IU Health:

1. Failure to implement or follow administrative, technical, and physical safeguards to protect the privacy of protected information
2. Failure to document disclosures of personal health information
3. Failure to implement or apply and document sanctions
4. Failure to appropriately train its workforce
5. Failure to notify patients of breach
6. Failure to mitigate harm
7. Violations of Indiana’s Deceptive Consumer Sales Act

The complaint is listed below.

Filed Complaint.pdf

Source:  Indiana Attorney General Rokita

Category: CourtHealthcareLawsU.S.

Post navigation

← WV: When asked for consent to search his house, def said ‘F*** it. Come on.’ That was consent.
GAO reports shortcomings in federal law enforcement on privacy and civil liberties →

Now more than ever

Search

Contact Me

Email: info@pogowasright.org

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

Categories

Recent Posts

  • CFPB Quietly Kills Rule to Shield Americans From Data Brokers
  • South Korea fines Temu for data protection violations
  • The BR Privacy & Security Download: May 2025
  • License Plate Reader Company Flock Is Building a Massive People Lookup Tool, Leak Shows
  • FTC dismisses privacy concerns in Google breakup
  • ARC sells airline ticket records to ICE and others
  • Clothing Retailer, Todd Snyder, Inc., Settles CPPA Allegations Regarding California Consumer Privacy Act Violations

RSS Recent Posts on DataBreaches.net

  • Breachforums Boss “Pompompurin” to Pay $700k in Healthcare Breach
  • HHS Office for Civil Rights Settles HIPAA Cybersecurity Investigation with Vision Upright MRI
  • Additional 12 Defendants Charged in RICO Conspiracy for over $263 Million Cryptocurrency Thefts, Money Laundering, Home Break-Ins
  • RIBridges firewall worked. But forensic report says hundreds of alarms went unnoticed by Deloitte.
  • Chinese Hackers Hit Drone Sector in Supply Chain Attacks
©2025 PogoWasRight.org. All rights reserved.
Menu
  • About
  • Privacy