- State
- CA
- Covered entity type
- Healthcare Provider
- Individuals affected
- 3,784
- Business associate present
- No
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On March 7, 2019, American Indian Health & Services, Inc. (the covered entity), discovered that a former employee had forwarded emails to a personal email account. These emails were forwarded in a manner that conflicted with the covered entity’s policies and procedures. The breach affected approximately 3,784 individuals’ electronic protected health information (ePHI). The ePHI involved included names, social security numbers, addresses, billing information, and insurance information. In response to the breach incident, the covered entity notified the affected individuals and prominent media outlets. Following OCR’s investigation, the covered entity implemented new administrative and technical safeguards and retrained its workforce members. The covered entity also provided OCR with assurances that the former employee’s access to the covered entity’s network was terminated.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.