- State
- CA
- Covered entity type
- Healthcare Provider
- Individuals affected
- 763
- Business associate present
- No
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- Other
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
The covered entity (CE) Community Family Care Medical Group IPA, Inc., submitted a breach report and subsequent addendum reporting that it had discovered that at least two of its former contracted physicians impermissibly disclosed its members protected health information (PHI) to competitor independent physicians associations (IPAs). According to the CE, the members’ PHI that the contracted physicians disclosed to the competitor IPAs included their names, addresses, dates of birth, Social Security, insurance identification numbers, health insurance information, as well as treatment, diagnosis and related information. The contracted physicians’ actions affected 7,173 individuals. The CE notified the affected individuals, completed media notification, and provided notification to HHS. OCR provided the CE with technical assistance regarding the CE’s obligations to safeguard PHI and to ensure it has met its Breach Notification Rule obligations.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.