Healthcare Providers Sued Over Physical Therapist’s Unauthorized Access to Nude Patient Images

A class action lawsuit has been filed against the University of Kansas Health System, Lawrence Memorial Hospital in Kansas, and Epic Systems by two women who had their nude images and sensitive health information accessed by a physical therapist without authorization when there was no treatment relationship with the patients.

Over a period of two years, an unnamed physical therapist employed by the University of Kansas Health System used his login credentials to access the nude photographs of breast augmentation patients. The patients had received services at Plastic Surgery Specialists of Lawrence, an unrelated plastic surgery clinic. The privacy breach was identified by the University of Kansas Health System on or around February 22, 2023. Following an investigation, the physical therapist was terminated, and the affected patients were notified about the privacy breach two months later. The patients were informed that a University of Kansas Health System employee had been discovered to have accessed their health information outside of his job duties between February 2021 and February 2023.

Plastic Surgery Specialists of Lawrence is affiliated with Lawrence Memorial Hospital, although neither entity is affiliated with the University of Kansas Health System. The physical therapist should not have been able to access patient data at either of those two entities; however, it was possible through Epic’s health information exchange platform, Care Everywhere, which allows data sharing with healthcare providers across the state of Kansas.

According to the lawsuit, the two Jane Doe patients never sought or received medical treatment at the University of Kansas Health System and never sought or received any treatment from the physical therapist. The lawsuit claims the physical therapist accessed photographs of women who had breast augmentation and other related procedures. In addition to nude photographs, the physical therapist accessed detailed body measurements and other sensitive health information.

The plaintiffs claim that the University of Kansas Health System attempted to downplay the incident by issuing a non-descript breach notification letter, failed to disclose the true nature of the privacy violations, and did not report the matter to law enforcement. The lawsuit claims that at least 425 patients, most likely female, who had undergone surgeries and procedures at Plastic Surgery Specialists of Lawrence had their photographs and other sensitive information viewed by the physical therapist.

According to the lawsuit, the University of Kansas Health System should have been aware of the unauthorized access and taken action against the employee sooner. Instead, the privacy violations continued for two years. The plaintiffs claim to have suffered profound emotional and psychological trauma as a result of the privacy violation, persistent anxiety when visiting healthcare providers or seeking treatment, as they have lost the trust that their health information will remain confidential. Further, the plaintiffs claim they are experiencing debilitating fear that they are being stalked, tracked, or targeted by the physical therapist.

HIPAA
Compliance
Checklist

Simple Guidelines
Immediate PDF Download

Immediate Access

Privacy Policy

Download Free Checklist

The plaintiffs’ lawsuit includes 13 causes of action, including negligence; negligent training, supervision, and retention; breach of express contract; breach of implied contract; invasion of privacy; intentional infliction of emotional distress; and violations of the Computer Fraud and Abuse Act and the Stored Communications Act. The plaintiffs seek a jury trial, damages, and an order from the court prohibiting the defendants from continuing to engage in unlawful acts, omissions, and practices.

About Liam Johnson

Liam Johnson has produced articles about HIPAA for several years. He has extensive experience in healthcare privacy and security. With a deep understanding of the complex legal and regulatory landscape surrounding patient data protection, Liam has dedicated his career to helping organizations navigate the intricacies of HIPAA compliance. Liam focusses on the challenges faced by healthcare providers, insurance companies, and business associates in complying with HIPAA regulations. Liam has been published in leading healthcare publications, including The HIPAA Journal. Liam was appointed Editor-in-Chief of The HIPAA Guide in 2023. Contact Liam via LinkedIn: https://www.linkedin.com/in/liamhipaa/