Back to the register

Port City Operating Company doing business as St. Joseph's Medical Center

ArchivedSubmitted 08/31/2018
State
CA
Covered entity type
Healthcare Provider
Individuals affected
4,984
Business associate present
Yes
Type of breach
Loss
Location of breached information
Other Portable Electronic Device
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

On August 9, 2018, the covered entity (CE), discovered that hard drives for two old laboratory machine analyzers, powered down for removal and replacement, were missing. The missing hard drives contained the electronic protected health information (ePHI) of approximately 4,984 individuals, including names, dates of birth, genders, account information, lab tests performed, test results, and the names of the physicians who ordered the tests. In response to the breach incident, the CE and its business associate, (BA), searched its facilities and interviewed its staff, but were unable to recover the missing hard drives. The CE provided breach notification to HHS, affected individuals, and the media. Following the breach, the CE ensured that its BA updated its policies and procedures and retrained workforce members. OCR obtained assurances that the CE/BA implemented the corrective actions listed above.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.