Back to the register

Dignity Health

ArchivedSubmitted 05/31/2018
State
CA
Covered entity type
Healthcare Provider
Individuals affected
55,947
Business associate present
Yes
Type of breach
Unauthorized Access/Disclosure
Location of breached information
Email
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

During a mass emailing of patient notifications in April 2018, Dignity Health, the covered entity (CE), used an email list incorrectly formatted by its business associate (BA), causing 55,947 individuals to receive an email intended for another individual. The protected health information (PHI) included the intended email recipient’s first name, last name, and physician name. The CE provided breach notification to HHS, affected individuals, and the media. OCR obtained assurances that the CE took voluntary corrective actions, including eliminating its use of personalized greetings in mass patient communications, updating its policies and procedures related to email communications, and designating one individual to review and approve all mass communication projects prior to transmittal.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.