Saturday, December 10 , 2016, 11:33 am | Partly Cloudy 62º


Local News

Class-Action Lawsuit Filed Against Cottage Health System Over Records Breach

Confidential medical information for more than 32,000 patients was disclosed publicly on the Internet for more than two months

A class-action lawsuit has been filed against Cottage Health System, claiming that the confidential information of more than 32,000 patients was put online for anyone to read, and was public for almost two months before the hospital system noticed.

The 15-page complaint states that between Oct. 8 and Dec. 2 of 2013, the confidential medical records of about 32,500 patients affiliated with Cottage Health System were negligently disclosed and released to the public on the Internet.

The records could be seen by anyone for that span of two months, the complaint states, adding that the "extent of the breach is enormous."

A statement from Cottage Hospital System said it takes its obligation to protect patient health information very seriously.

"We have notified the patients involved in the recent data disclosure, and will continue to investigate the unique circumstances that led to this event," the statement said, but added that Cottage is unable to comment on an active lawsuit.

The case includes former patient Kenneth Rice and others who had their records revealed, and is against the corporation inSync, a Laguna Hills-based company responsible for putting the records in a secure location online, and Cottage Health System, which has hospitals in Santa Barbara, Goleta and Santa Ynez.

The affected records are from people who attended any of Cottage's hospitals from Sept. 29, 2009, to Dec. 2, 2013.

Rice sought treatment at Cottage Hospital on multiple occasions, and provided the hospital with confidential information but never authorized the release of that information.

The complaint alleges that inSync "failed to provide any encryption or other security to prevent anyone from reading the medical records."

On Dec. 2, Cottage was contacted by a third party, who informed it that he was able to read the confidential records of patients online.

"How was it possible that the medical records could be placed in the public domain of the Internet, for anyone to view for two months, without Cottage Hospital detecting that anyone surfing the Internet could view the confidential medical record of 32,500 of its patients? The only answer is that Cottage Health was completely negligent in its obligations under the CMIA and HIPAA," the lawsuit states.

Rice received a letter on Dec. 6 stating that his confidential records had ended up on the Internet.

The case was filed in Orange County Superior Court on Jan. 27 by L.A.-based attorney Brian Kabatek and Don Ernst of Ernst Law Group APC in San Luis Obispo. 

The complaint asks for a jury trial and at least $1,000 in damages per class member.

Noozhawk staff writer Lara Cooper can be reached at .(JavaScript must be enabled to view this email address). Follow Noozhawk on Twitter: @noozhawk, @NoozhawkNews and @NoozhawkBiz. Connect with Noozhawk on Facebook.

Reader Comments

Noozhawk's intent is not to limit the discussion of our stories but to elevate it. Comments should be relevant and must be free of profanity and abusive language and attacks.

By posting on Noozhawk, you:

» Agree to be respectful. Noozhawk encourages intelligent and impassioned discussion and debate, but now has a zero-tolerance policy for those who cannot express their opinions in a civil manner.

» Agree not to use Noozhawk’s forums for personal attacks. This includes any sort of personal attack — including, but not limited to, the people in our stories, the journalists who create these stories, fellow readers who comment on our stories, or anyone else in our community.

» Agree not to post on Noozhawk any comments that can be construed as libelous, defamatory, obscene, profane, vulgar, harmful, threatening, tortious, harassing, abusive, hateful, sexist, racially or ethnically objectionable, or that are invasive of another’s privacy.

» Agree not to post in a manner than emulates, purports or pretends to be someone else. Under no circumstances are readers posting to Noozhawk to knowingly use the name or identity of another person, whether that is another reader on this site, a public figure, celebrity, elected official or fictitious character. This also means readers will not knowingly give out any personal information of other members of these forums.

» Agree not to solicit others. You agree you will not use Noozhawk’s forums to solicit and/or advertise for personal blogs and websites, without Noozhawk’s express written approval.

Noozhawk’s management and editors, in our sole discretion, retain the right to remove individual posts or to revoke the access privileges of anyone who we believe has violated any of these terms or any other term of this agreement; however, we are under no obligation to do so.

Support Noozhawk Today

You are an important ally in our mission to deliver clear, objective, high-quality professional news reporting for Santa Barbara, Goleta and the rest of Santa Barbara County. Join the Hawks Club today to help keep Noozhawk soaring.

We offer four membership levels: $5 a month, $10 a month, $25 a month or $1 a week. Payments can be made through PayPal below, or click here for information on recurring credit-card payments.

Thank you for your vital support.

Daily Noozhawk

Subscribe to Noozhawk's A.M. Report, our free e-Bulletin sent out every day at 4:15 a.m. with Noozhawk's top stories, hand-picked by the editors.

Sign Up Now >