Back to the register

VA Palo Alto Health Care System

ArchivedSubmitted 03/26/2018
State
CA
Covered entity type
Healthcare Provider
Individuals affected
1,600
Business associate present
No
Type of breach
Unauthorized Access/Disclosure
Location of breached information
Paper/Films
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

The VA Palo Alto Health Care System, a Veteran’s Affairs facility and covered entity (CE), reported a breach incident affecting 1,600 individuals in December 2017. During a mass mailing to recruit for a research study, the research study worker used an electronic mail merge and mixed up names and addresses on mailed postcards. The postcards contained protected health information (PHI), including clinical and demographic information. The VA provided breach notification to individuals, HHS, and the media. OCR obtained assurances that the VA took voluntary corrective action by re-sending the postcards correctly, training research study staff on proper handling of PHI and on the mail merge system, and revising its procedure so that a second person checks mail merged documents against a master list before mailing.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.