- State
- CA
- Covered entity type
- Healthcare Provider
- Individuals affected
- 55,947
- Business associate present
- Yes
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
During a mass emailing of patient notifications in April 2018, Dignity Health, the covered entity (CE), used an email list incorrectly formatted by its business associate (BA), causing 55,947 individuals to receive an email intended for another individual. The protected health information (PHI) included the intended email recipient’s first name, last name, and physician name. The CE provided breach notification to HHS, affected individuals, and the media. OCR obtained assurances that the CE took voluntary corrective actions, including eliminating its use of personalized greetings in mass patient communications, updating its policies and procedures related to email communications, and designating one individual to review and approve all mass communication projects prior to transmittal.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.