Local Sources- Attorney General Todd Rokita filed a lawsuit against IU Health and IU Healthcare Associates for accused failure to properly report, review, and enforce HIPAA and Indiana law violations.
“We will continue to uphold and protect Hoosier patients’ medical privacy,” Attorney General Rokita said. “Trust is the foundation of the patient-doctor relationship. Without trust, we don’t have reliable, honest healthcare.”
This issue was first brought to the AG office's attention in 2022 when a 10-year-old rape victim and her mother went to an IU hospital for an abortion, as a result of the rape and abuse the child endured.
The lawsuit alleges after the abortion, while the mother and daughter were still at the hospital for recovery and observation, they were greeted with a front-page news story in the Indianapolis Star, which described the 10-year-old's case in great detail. This article went public, and the story became worldwide household news after the doctor spoke to a reporter at a political rally, which was also alleged.
In a release, Rokita's office says neither the little girl nor her mother gave the doctor authorization to speak to the media about their case.
On July 15, 2022, hospital administrators emailed statements to multiple media outlets informing them that they had conducted a review and “found the doctor in compliance with privacy laws.”
On May 25, 2023, the Indiana Medical Licensing Board conducted a hearing and determined that the doctor violated HIPAA by improperly disclosing patient information and for improperly de-identifying patient information, and the doctor violated the Indiana patient confidentiality rule by failing to get patient permission prior to disclosing any information.
The following day, IU Health issued a public statement in which it disagreed with the Medical Licensing Board’s determination once again claiming the doctor did not violate privacy laws.
Subsequent to the Medical License Board hearing, the office says they "Discovered numerous instances where IU Health has sanctioned non-physician employees with termination for far less egregious patient privacy violations but has failed to implement or enforce similar privacy policies or sanctions for its physicians."
“Doctors and all health care professionals should be able to rely on their employers and patients should be able to trust their doctors,” Attorney General Rokita said. “When a hospital or other healthcare provider makes your private medical information public, that trust is decimated. As a result, the quality, delivery, and sustainability of our healthcare is significantly weakened.”
The lawsuit consists of the following seven counts against IU Health:
- Failure to implement or follow administrative, technical, and physical safeguards to protect the privacy of protected information
- Failure to document disclosures of personal health information
- Failure to implement or apply and document sanctions
- Failure to appropriately train its workforce
- Failure to notify patients of breach
- Failure to mitigate harm
- Violations of Indiana’s Deceptive Consumer Sales Act