Back to the register
Port City Operating Company doing business as St. Joseph's Medical Center
ArchivedSubmitted 08/31/2018
- State
- CA
- Covered entity type
- Healthcare Provider
- Individuals affected
- 4,984
- Business associate present
- Yes
- Type of breach
- Loss
- Location of breached information
- Other Portable Electronic Device
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On August 9, 2018, the covered entity (CE), discovered that hard drives for two old laboratory machine analyzers, powered down for removal and replacement, were missing. The missing hard drives contained the electronic protected health information (ePHI) of approximately 4,984 individuals, including names, dates of birth, genders, account information, lab tests performed, test results, and the names of the physicians who ordered the tests. In response to the breach incident, the CE and its business associate, (BA), searched its facilities and interviewed its staff, but were unable to recover the missing hard drives. The CE provided breach notification to HHS, affected individuals, and the media. Following the breach, the CE ensured that its BA updated its policies and procedures and retrained workforce members. OCR obtained assurances that the CE/BA implemented the corrective actions listed above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.