- State
- WA
- Covered entity type
- Healthcare Provider
- Individuals affected
- 2,300
- Business associate present
- No
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- Desktop Computer
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
The covered entity’s (CE) Operations Director allowed her husband, a non-employee to access the CE’s office and computer in an effort to aid her with her work. The computer had access to the CE’s electronic medical records system which contained approximately 2,531 individuals’ electronic protected health information (ePHI). The ePHI potentially affected by the breach included names, social security numbers, addresses, driver’s license numbers, dates of birth, diagnoses, lab results and medications. In response to the breach incident, the CE sanctioned its workforce member. Following OCR’s investigation, the CE provided breach notification to the affected individuals and the media, updated its policies and procedures, and retrained workforce members.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.