Back to the register

Good Samaritan Hospital, Inc.

ArchivedSubmitted 04/17/2020
State
CA
Covered entity type
Healthcare Provider
Individuals affected
233,835
Business associate present
No
Type of breach
Hacking/IT Incident
Location of breached information
Email
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

The covered entity (CE), Good Samaritan Hospital, Inc. reported that it experienced a series of phishing email attacks, which resulted in the breach of 233,835 individuals’ protected health information (PHI). The CE became a part of PIH Health, Inc. (PIH Health) in December 2019, and OCR consolidated its investigation of this breach with another breach involving email phishing attacks against PHI Health, which we settled with a resolution agreement and corrective action plan. The settlement resolves an investigation that OCR conducted after receiving PIH Health’s breach report, which stated that in June 2019, a phishing attack compromised forty-five of its employees’ email accounts, resulting in the breach of 189,763 individuals’ unsecured electronic PHI. PIH Health reported that the ePHI disclosed in the phishing attack included affected individuals’ names, addresses, dates of birth, driver’s license numbers, Social Security numbers, diagnoses, lab results, medications, treatment and claims information, and financial information. OCR’s investigation found multiple potential violations of the HIPAA Rules. Under the terms of the resolution agreement, PIH Health has agreed to implement a corrective action plan that will be monitored by OCR for two years and paid a $600,000 settlement to OCR. Under the corrective action plan, PIH is obligated to take definitive steps toward resolving potential violations of the HIPAA Rules, including: (1) conducting an accurate and thorough risk analysis of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of its ePHI; (2) developing and implementing a risk management plan to address and mitigate security risks and vulnerabilities identified in its risk analysis; (3) developing, maintaining, and revising, as necessary, its written policies and procedures to comply with the HIPAA Rules; and (4) training its workforce members who have access to PHI on its HIPAA policies and procedures. The resolution agreement and corrective action plan may be found at: https://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/agreements/index.html.

Change history

  • 9/23/2026Added to OCR's archive list

Source: U.S. Department of Health and Human Services, Office for Civil Rights, Breach Portal. Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.