A MEDICAL CORPORATION CAN BE LIABLE IN TORT FOR FAILURE TO SAFEGUARD THE CONFIDENTIALITY OF MEDICAL RECORDS (FOURTH DEPT).
The Fourth Department, reversing (modifying) Supreme Court, determined the complaint against defendant medical corporations stated a cause of action for negligent failure to safeguard the confidentiality of medical records:
Plaintiffs commenced this action alleging that, attendant to the health care services they received from defendant Rochester General Hospital (RGH), confidential medical records were generated and that those confidential medical records were stored on computer systems and networks maintained by RGH and defendants Rochester Regional Health ACO, Inc. (RRH) and Greater Rochester Independent Practice Association, Inc. (GRIPA). Plaintiffs further allege that defendant Christine M. Smith, R.N., a nurse at RGH, impermissibly accessed those records due to the failure of RGH, RRH and GRIPA “to exercise reasonable care in obtaining, retaining, securing, safeguarding, and protecting this confidential medical information from unlawful access.”
“A medical corporation may . . . be liable in tort for failing to establish adequate policies and procedures to safeguard the confidentiality of patient information or to train their employees to properly discharge their duties under those policies and procedures. These potential claims provide the requisite incentive for medical providers to put in place appropriate safeguards to ensure protection of a patient’s confidential information” … . Here, plaintiffs alleged that defendants generated and maintained the medical records that Smith impermissibly accessed and that they breached their duty to properly safeguard or monitor access to those records. Accepting as true the allegations in the complaint and the averments in the affidavits submitted in opposition to the motion, we conclude that plaintiffs have sufficiently alleged a negligence claim. * * * Hurley v Rochester Regional Health Aco, Inc., 2025 NY Slip Op 01729, Fourth Dept 3-21-25
Practice Point: A medical corporation can be liable for failure to safeguard the confidentiality of medical records.