- State
- CA
- Covered entity type
- Healthcare Provider
- Individuals affected
- 1,600
- Business associate present
- No
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- Paper/Films
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
The VA Palo Alto Health Care System, a Veteran’s Affairs facility and covered entity (CE), reported a breach incident affecting 1,600 individuals in December 2017. During a mass mailing to recruit for a research study, the research study worker used an electronic mail merge and mixed up names and addresses on mailed postcards. The postcards contained protected health information (PHI), including clinical and demographic information. The VA provided breach notification to individuals, HHS, and the media. OCR obtained assurances that the VA took voluntary corrective action by re-sending the postcards correctly, training research study staff on proper handling of PHI and on the mail merge system, and revising its procedure so that a second person checks mail merged documents against a master list before mailing.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.