- State
- CA
- Covered entity type
- Healthcare Provider
- Individuals affected
- 1,049
- Business associate present
- No
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On March 12, 2018, RoxSan Pharmacy, Inc., the covered entity (CE), reported to OCR that an impermissible disclosure of electronic protected health information (ePHI) occurred on January 20, 2015, when an employee of the CE emailed a spreadsheet containing ePHI to an attorney representing an employee of a business associate. The spreadsheet contained the ePHI of approximately 1,049 individuals. The ePHI included patient information, such as insurance information, prescription information, and physician names. The CE determined that the disclosure was impermissible because it was not made for the purposes of treatment, payment, or health care operations. The CE provided notice to HHS, individual notification, and media notification. OCR obtained documentation of the individual and media breach notifications. OCR also obtained documentation showing that the CE took the following steps in response to the breach and OCR’s corresponding investigation: (1) the CE updated its policies and procedures addressing the use and disclosure of PHI, safeguarding PHI, de-identifying PHI, and employee sanctions for noncompliance with HIPAA; (2) the employee responsible for the breach was sanctioned and counseled on how to better safeguard PHI to prevent future breach incidents; and (3) all employees of the CE were retrained on the updated policies and procedures.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.