Back to the register

West Hills Hospital & Medical Center

ArchivedSubmitted 08/06/2019
State
CA
Covered entity type
Healthcare Provider
Individuals affected
10,650
Business associate present
Yes
Type of breach
Hacking/IT Incident
Location of breached information
Network Server
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

On June 12, 2019, a business associate (BA), United WestLabs, Inc., notified the covered entity (CE), that its subcontractor, American Medical Collection Agency, experienced a security incident between August 1, 2018 and March 30, 2019, when an unauthorized user gained access to the subcontractor’s computer server. The incident affected individuals across several different CEs including West Hills Hospital & Medical Center. The types of electronic protected health information (ePHI) involved in the incident included names, addresses, medical account numbers, dates of services, amounts paid, referring doctors’ codes, and disposition codes. The CE provided breach notification to HHS, affected individuals, and the media. Following the breach, the CE ceased sending collection accounts to the subcontractor. OCR obtained documentation of the applicable BA agreements and obtained assurances that the CE implemented the corrective action steps listed above.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.