VA Medical Center Patient Privacy and Malpractice Risks
This paper examines risk management issues at the Oklahoma City VA Medical Center (OKC VAMC), one of the nation's largest tertiary care facilities serving veterans. It provides an overview of the facility's scope and recent care-quality scandals, then analyzes the tension between patient confidentiality and information accessibility under HIPAA, documenting more than 10,000 privacy breaches recorded by the VA since 2011. The paper also compares physician responsibilities under informed and implied consent frameworks, surveys malpractice and liability exposure under the Federal Tort Claims Act, and recommends practical measures — including stronger EHR access controls and greater institutional accountability — to reduce future risk.
- Overview of the Oklahoma City VA Medical Center: Facility scope, services, and recent care scandals
- Patient Confidentiality Challenges and HIPAA Violations: ePHI breaches, HIPAA failures, and documented abuse examples
- Informed Consent vs. Implied Consent: Rights and Responsibilities: Physician duties under informed and implied consent frameworks
- Malpractice and Liability Risk at the OKC VAMC: Federal Tort Claims Act exposure and settlement history
- Recommended Measures to Minimize Risk: EHR access controls, accountability, and scheduling reform
- Conclusion: Cultural reform needed for lasting systemic improvement
✍️ How to write this paper — guide, tools & examples ▾
What makes this paper effective
- It grounds abstract risk management concepts in concrete, real-world examples — including named veteran patients and documented incident timelines — making the argument vivid and persuasive.
- It moves logically from description (what the facility is) to diagnosis (what the problems are) to prescription (what should be done), giving the paper a clear and professional structure.
- It integrates legal frameworks (HIPAA, the Federal Tort Claims Act) with ethical concepts (informed vs. implied consent) to demonstrate that healthcare risk management sits at the intersection of law, ethics, and organizational culture.
Key academic technique demonstrated
The paper effectively uses authoritative secondary sources — government reports, peer-reviewed journal articles, and investigative journalism — to build an evidence-based argument. Rather than relying on a single type of source, it triangulates across multiple independent accounts (Westwood, Waldman & Ornstein, Slack) to establish the scale and severity of the VA's privacy violations, strengthening the credibility of each claim.
Structure breakdown
The paper follows a five-part analytical structure: (1) a contextual overview of the OKC VAMC's mission and recent controversies; (2) a detailed examination of HIPAA compliance failures and how ePHI is abused; (3) a conceptual comparison of informed and implied consent; (4) a quantified summary of malpractice exposure; and (5) practical risk-reduction recommendations. The conclusion ties organizational culture to all preceding issues, framing systemic reform as the only durable solution.
Overview of the Oklahoma City VA Medical Center
The OKC VAMC provides a wide range of tertiary healthcare services, including psychiatry, physical medicine and rehabilitation, and medical-surgical units, as well as numerous specialty clinics. These include the Mental Health Intensive Case Management (MHICM) program, the Reaching Out to Educate and Assist Health Care Families (REACH) program, a Homeless Program/Compensated Work Therapy initiative, a regional referral center for open-heart surgery, Telehealth Care Coordination, a Center for Alzheimer and Neurodegenerative Diseases, Animal Assisted Therapy, and a High Risk Foot Program — along with various social services (About the Oklahoma City VA Medical Center, 2016). The OKC VAMC features 192 beds, serves 48 counties in Oklahoma and two north-central Texas counties, and operates an annex clinic in north Oklahoma City (About the Oklahoma City VA Medical Center, 2016).
This medical center has recently been implicated in a VA-wide scandal concerning lengthy waiting times and the provision of suboptimal medical care that may have jeopardized the lives of dozens, if not hundreds, of veteran patients. For instance, a high-profile report by Donovan Slack (2015) in USA Today cites the specific cases of two veterans, Charles Hand and George Washington Purifoy, who were patients at the OKC VAMC. According to Slack, "Both sought care at Veterans' Affairs medical facilities in Oklahoma. And in their cases and others, medical professionals missed or misdiagnosed their conditions resulting in life-altering consequences" (2015, para. 2).
Patient Confidentiality Challenges and HIPAA Violations
Like other VA medical centers, the OKC VAMC uses an electronic health record (EHR) system to facilitate healthcare providers' access to patient data (What is VistA?, 2016). The ready accessibility of electronic protected health information (ePHI) through the EHR system, combined with frequent VA employee incompetence, has resulted in thousands of violations of the Health Insurance Portability and Accountability Act (HIPAA) since its passage in 1996 (Westwood, 2016). According to Lawley (2012), "ePHI is defined as any Protected Health Information (PHI) that is stored on any form of electronic media, or which is transmitted in any electronic form (e.g., fax or Internet). This would include scanned records or correspondence that is written on a computer and then printed" (p. 19). The HIPAA agency has recorded more ePHI and other patient privacy complaint violations by the VA than by any other healthcare provider in the country (Waldman & Ornstein, 2015). As Westwood (2016) emphasizes, "Department of Veterans Affairs officials have racked up more than 10,000 privacy breaches since 2011, making the VA the nation's most prolific violator of laws protecting patients' personal medical information" (p. 3).
Despite the flagrant nature of many of these violations — which investigators determined to be intentional and malicious — no official sanction of the VA has been issued to date (Westwood, 2016). The challenges of providing patient confidentiality pursuant to HIPAA and professional codes of conduct therefore involve both accidental and intentional privacy violations (Westwood, 2016). Accidental violations represent an area of deficiency that can be addressed through remedial training, while intentional violations present an especially difficult challenge that must be addressed on a case-by-case basis. For instance, many privacy violations involved veterans who were also VA employees whose ePHI were accessed by spouses or co-workers for use in divorce proceedings, by VA management investigating whistleblowing activities, or simply "out of curiosity" following suicides or suicide attempts by veteran employees (Waldman & Ornstein, 2015, para. 6). Some salient examples of these abuses include the following:
In September 2011, after a veteran committed suicide on the grounds of a VA facility in Biloxi, Mississippi, more than 40 employees accessed his medical records. In September 2013, a VA employee who worked at the same Biloxi facility committed suicide, and again several co-workers inappropriately accessed the employee's medical records. In January 2015, a veteran employed at the C.W. Bill Young VA Medical Center attempted suicide; afterward, many co-workers who had no direct involvement in his medical care appeared to know about his attempt and asked how he was doing. Following an investigation, the VA's incident response team found that an employee had indeed inappropriately accessed the veteran's medical records "out of curiosity" (Waldman & Ornstein, 2015, para. 7).
Unfortunately, these privacy violations are only a few of the thousands of such violations that have been reported to HIPAA in recent years, despite the VA's efforts to provide ongoing employee training on the proper handling of patient information (Waldman & Ornstein, 2015).
Informed Consent vs. Implied Consent: Rights and Responsibilities
Informed consent involves formally providing patients with the information they need to make a decision about the type of medical care they want or do not want, even if clinicians disagree with that choice (Curran, 2012). As Curran reports, "Once a patient is properly informed, it is the patient's right to choose among the various alternatives rather than a physician's right to prescribe the 'best' treatment, even when that choice may be the more dangerous treatment" (p. 134). Pursuant to the reasonable care provider standard, clinicians are generally responsible for providing patients with information concerning (a) the purpose of the proposed treatment, (b) its risks and benefits, (c) available alternatives, including the risks and benefits of those alternatives, and (d) the effect of receiving no treatment at all (Curran, 2012).
By contrast, the term "implied consent" refers to situations in which patients are presumed to give their consent to medical treatment when they are otherwise unable to do so expressly, as with informed consent (Breen & Plueckhahn, 2002). Implied consent also extends to the sharing of patient information among healthcare providers, even when the patient has not expressly authorized this. As Breen and Plueckhahn (2002) report, "In many health care situations, consent for sharing confidential information between members of the 'health care team' is implied and it is presumed that patients know and accept that this will happen" (p. 39). The overarching factor to be considered in both informed and implied consent situations is the best interests of the patient (Breen & Plueckhahn, 2002).
Conclusion
The research showed that as the nation's largest healthcare provider, it is not surprising that the Veterans Health Administration has been cited for various patient privacy violations and malpractice claims. What is surprising, however, is just how severe these problems are and how resistant they appear to be to even the most rigorous efforts to address them. Clearly, the organizational culture at the VA must change from the top down in order to effect the meaningful reforms needed to eliminate the flagrant abuses identified in this research and to ensure that veteran patients receive the best quality of healthcare that American taxpayer money can provide — an outcome that is not currently being achieved, as evidenced by the number of medical malpractice suits brought against the agency in recent years.
References
About the Oklahoma City VA Medical Center. (2016). Oklahoma City VA Medical Center. Retrieved from
About VA. (2016). Department of Veterans Affairs. Retrieved from http://www.va.gov/about_va/vahistory.asp.
Breen, K. J., & Plueckhahn, V. D. (2002). Ethics, law, and medical practice. St. Leonards, NSW: Allen & Unwin.
Carter, P. (2016). How to fix the VA. Slate. Retrieved from
Curran, K. A. (2012, October 1). Informed consent: A right without a remedy examined through the lens of maternity care. The American University Journal of Gender, Social Policy & the Law, 21(1), 133–142.
Lawley, M. (2012). HIPAA compliance guide. [Publisher details not provided in source].
Slack, D. (2015). Veterans still suffering from poor VA care despite fixes touted in Washington. USA Today. Retrieved from http://www.usatoday.com/story/news/politics/2015/12/22/veterans-suffering-poor-va-care-despite-washington-fixes/77556860/.
Veteran medical malpractice. (2016). Lawyers and Settlements. Retrieved from
Waldman, A., & Ornstein, C. (2015, December 30). Privacy violations rising at Veterans Affairs medical centers. National Public Radio. Retrieved from http://www.npr.org/sections/health-shots/2015/12/30/461400692/patient-privacy-isn-t-safeguarded-at-veterans-medical-facilities.
Westwood, S. (2016, January 6). Medical privacy is not the VA way. Examiner (Washington, D.C.), 3.
What is VistA? (2016). Department of Veterans Affairs. Retrieved from
Create your account
Always verify citation format against your institution’s current style guide requirements.