- State
- CA
- Covered entity type
- Healthcare Provider
- Individuals affected
- 46,632
- Business associate present
- No
- Type of breach
- Hacking/IT Incident
- Location of breached information
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
The covered entity (CE) reported that two workforce members responded to a phishing email which resulted in a breach of protected health information (PHI). The breach affected 44,960 individuals and included names, addresses, dates of birth, health care claims information, diagnoses, medications, other treatment information, and 3,304 social security numbers. The CE provided breach notification to HHS, affected individuals and the media. Following the breach, the CE took a number of steps to strengthen its administrative and technical safeguards. It increased its security training and enhanced authentication procedures and technical measures to identify and remove malicious emails. OCR’s investigation resulted in the CE improving its practices in safeguarding PHI.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.