Avir at Rose Trail: Resident SSNs Left in Public Lobby - TX
That is what federal inspectors found when they visited the facility on December 31, 2025.
The binder was kept in the lobby, the administrator told inspectors, so that members of the public could review what violations had been cited at the facility and how management planned to fix them. That part was intentional. What ended up inside the binder was not, she said.
Along with the expected regulatory paperwork, the binder contained resident care plans with private health information, a Patient Incident Report from July 2025 listing the names, Social Security numbers, Medicaid numbers, Medicare numbers, and health diagnoses of at least two residents, and a resident identifier sheet that matched resident names to numbered codes, along with a survey document containing additional private information. The administrator said she did not know who placed those documents in the binder.
She was clear about what it meant. "A resident's care plan should not have been in the binder as that was protected health information with diagnoses, treatment and other personal information that should not have been readily available to the public," she told inspectors. She said the same about the incident report. It was her responsibility, and every staff member's responsibility, to make sure that information never reached unauthorized eyes.
How long the binder sat there with those documents inside, and how many people may have read them, the inspection report does not say.
The Director of Nursing, who told inspectors he had been in his position for only a couple of weeks at the time of the inspection, said all staff were trained to protect resident privacy during new hire onboarding and through regular in-service sessions throughout the year. He said he would make sure that training was reinforced. The Assistant Director of Nursing made the same point about training, and added something specific about the stakes: the information sitting in that binder, including names, dates of birth, Social Security numbers, and health diagnoses, was exactly the kind of information someone could use to exploit a vulnerable person.
Social Security numbers and Medicaid and Medicare account numbers are among the most sensitive identifiers a person carries. For elderly nursing home residents, who may have limited ability to monitor their own financial accounts or respond quickly to fraud, exposure of that information carries particular risk. The ADON called it plainly what it was: a HIPAA violation.
The facility's own privacy policy, dated April 2025, stated that all patient information was considered privileged and confidential, that access required proper authorization, and that personal medical information would be maintained as confidential unless the resident authorized its release.
The inspection was prompted by a complaint. Inspectors cited the violation at a level of minimal harm or potential for actual harm, meaning they did not find evidence that a resident had yet suffered a concrete consequence from the exposure. That finding reflects what inspectors could document, not necessarily what may have occurred before they arrived.
The administrator's account raises a question the report does not answer: if no one knew who placed the care plans, incident report, and identifier sheets into a public binder, then no one was watching what went into it. The binder was in the lobby. The documents were there. And for however long that was true, the private lives of at least two residents, their illnesses, their government benefit numbers, their identities, were available to anyone who reached for it.
Full Inspection Report
The details above represent a summary of key findings. View the complete inspection report for Avir At Rose Trail from 2026-01-02 including all violations, facility responses, and corrective action plans.
Download the official CMS inspection PDF from Medicare.gov
Additional Resources
Data source: This article is based on inspection data downloaded directly from the Centers for Medicare & Medicaid Services (CMS) via Medicare.gov. CMS releases inspection reports in bulk; we publish the findings as documented by state surveyors in the official Form CMS-2567 Statement of Deficiencies.
Plan of correction: The CMS report we receive does not include the facility's plan of correction. Facilities submit plans of correction separately to state survey agencies and those responses may not be reflected in CMS data at the time of publication. The absence of a plan of correction in our data does not mean one was not filed. Readers who want information about corrective steps taken are encouraged to contact the facility directly or their state survey agency.
Corrections may have occurred: Inspection reports reflect conditions observed on the date of the survey. Facilities may have implemented corrections, staffing changes, additional training, or other remediation since the report was issued. We report what CMS provides and encourage readers to seek current information from the facility.
Editorial process: Inspection findings are extracted from CMS source documents and synthesized using AI, reviewed for factual accuracy against the original report by our editorial team.
Professional review: All content reviewed by Christopher F. Nesbitt, Sr., NH EMT & BU-trained Paralegal.
Last verified: September 19, 2026 · Our methodology
Avir at Rose Trail in TYLER, TX was cited for violations during a health inspection on January 2, 2026.
That is what federal inspectors found when they visited the facility on December 31, 2025.
Health inspections identify deficiencies that facilities must correct. Violations range from minor documentation issues to serious safety concerns. Review the full report below for specific details and facility response.