- State
- CA
- Covered entity type
- Healthcare Provider
- Individuals affected
- 1,272
- Business associate present
- No
- Type of breach
- Loss
- Location of breached information
- Paper/Films
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On October 27, 2017, the covered entity (CE), SAY San Diego, was notified by the County of San Diego Health & Human Services Agency that a citizen had returned paper files containing protected health information (PHI) to its office that were found in a filing cabinet purchased from a salvage store. The CE confirmed that the files were related to youth participants in its dual diagnosis program from January through June 2013. The breach included the clinical and demographic information of 1,272 individuals. The CE provided breach notification to affected individuals, prominent media outlets, and HHS and offered individuals one year of free identity monitoring services. In response to OCR’s investigation, the CE revised its policy and procedure on the disposal of PHI and electronic PHI and provided additional training to the workforce member responsible for the breach.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.