- State
- WA
- Covered entity type
- Healthcare Provider
- Individuals affected
- 569
- Business associate present
- No
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- Electronic Medical Record
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On May 26, 2017, the covered entity (CE), Kennewick General Hospital d/b/a as Trios Health, reported that one of its workforce members impermissibly accessed protected health information (PHI) that was outside the scope of the job responsibilities. The breach potentially affected 1,603 individuals. The types of PHI involved in the breach included patients' names, social security numbers, addresses, dates of birth, driver’s license numbers, lab results, medication information, treatment information, diagnoses and medical conditions. Following the breach, investigated the breach, sanctioned the involved workforce member, and implemented safeguards, including placing additional restrictions on access to PHI. As a result of OCR’s investigation, the CE conducted a review of its policies and procedures to determine the potential risks to its PHI and electronic PHI, revised its policies, and retrained its workforce.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.