Las Palmas Del Sol Healthcare told 1,854 patients a former employee viewed their records

Organization
Las Palmas Del Sol Healthcare (El Paso Healthcare System, Ltd.)
Exploit
Malicious Insider
Industry
Healthcare

Las Palmas Del Sol Healthcare, the El Paso, Texas hospital system operated by El Paso Healthcare System, Ltd., notified 1,854 patients that a former employee had accessed their medical records without a work-related reason.

The organization said the inappropriate access occurred between January 1, 2018 and March 12, 2021, and that the employee may have disclosed what they saw to other unauthorized individuals. The records involved patient names, addresses, dates of birth, health plan information, hospital account numbers and clinical detail such as the reason for a visit and diagnosis information. Las Palmas Del Sol said Social Security numbers, driver's license numbers, credit card details and bank account information were not accessed or disclosed.

The employee was terminated and their login credentials revoked, and the conduct was reported to law enforcement. According to HIPAA Journal, a law enforcement investigation delayed patient notification, which was not issued until December 2024. The health system said it would introduce systematic auditing and monitoring of employee access to patient records and reinforce staff training on permissible access.

Sources differ on when the activity was discovered. The substitute notice published on the health system's own website dates the discovery to February 23, 2023, while HIPAA Journal reported it as February 23, 2024. Neither account explains why the record access stopped in March 2021 although the employee remained on staff until the investigation.

Sources