- State
- CA
- Covered entity type
- Healthcare Provider
- Individuals affected
- 15,000
- Business associate present
- No
- Type of breach
- Theft
- Location of breached information
- Desktop Computer, Electronic Medical Record, Email, Laptop, Other, Other Portable Electronic Device, Paper/Films
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
A workforce member of the covered entity (CE), Advanced ENT Head and Neck Surgery, surreptitiously took pictures of patients, recorded conversations with patients, and made paper copies of patients’ legal identification, payment information, and paper medical records. The workforce member also stole several mobile devices containing electronic protected health information (ePHI) and in some cases, posted the breached information to a social media account. The breach affected approximately 15,000 individuals, and the types of PHI and ePHI involved included clinical, demographic and financial information. The CE provided breach notification to HHS and also notified other enforcement agencies with jurisdiction over the breach incident. In response to the breach, which the CE discovered around May 1, 2017, the CE adopted encryption technologies, improved password requirements, updated its Security Rule Risk Management Plan, implemented new technical safeguards, improved physical security, and revised its HIPAA policies and procedures. The CE also sanctioned the involved workforce member, which in this case included terminated of employment. OCR has closed its investigation because this case has been accepted for investigation by the Department of Justice.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.