Back to the register

SAY San Diego

ArchivedSubmitted 12/22/2017
State
CA
Covered entity type
Healthcare Provider
Individuals affected
1,272
Business associate present
No
Type of breach
Loss
Location of breached information
Paper/Films
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

On October 27, 2017, the covered entity (CE), SAY San Diego, was notified by the County of San Diego Health & Human Services Agency that a citizen had returned paper files containing protected health information (PHI) to its office that were found in a filing cabinet purchased from a salvage store. The CE confirmed that the files were related to youth participants in its dual diagnosis program from January through June 2013. The breach included the clinical and demographic information of 1,272 individuals. The CE provided breach notification to affected individuals, prominent media outlets, and HHS and offered individuals one year of free identity monitoring services. In response to OCR’s investigation, the CE revised its policy and procedure on the disposal of PHI and electronic PHI and provided additional training to the workforce member responsible for the breach.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.