- State
- CA
- Covered entity type
- Healthcare Provider
- Individuals affected
- 18,637
- Business associate present
- No
- Type of breach
- Theft
- Location of breached information
- Other Portable Electronic Device
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
The covered entity (CE), Pacific Ocean Pediatrics, reported a breach when three computers and two external hard drives were stolen from the CE’s office after a cleaning crew member left an exterior door unlocked. The breach affected approximately 18,637 individuals, who were the CE’s patients and parents of patients. The protected health information (PHI) included names, addresses, dates of birth, phone numbers, sex, insurance information, and entire charted medical history of patients including symptoms, tests, diagnosis, and prescriptions. The CE immediately reported the theft to law enforcement. The CE provided timely breach notification to HHS, affected individuals, and the media. Substitute notice was also provided. The CE consulted with an IT professional to implement additional protective measures to prevent a similar breach occurring in the future. Following the incident, the CE improved physical security at its facility, installed a firewall, encrypted electronic devices that store PHI, and adopted new and revised policies and procedures to safeguard PHI. The CE has trained workforce members on the new and revised policies. OCR obtained assurances that the CE implemented the corrective actions noted above. OCR also provided the CE technical assistance regarding the risk analysis and risk management provisions of the Security Rule.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.