- State
- AZ
- Covered entity type
- Healthcare Provider
- Individuals affected
- 6,599
- Business associate present
- No
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On January 12, 2017, an employee inadvertently emailed an attachment containing patient invoices for December 2016 to six current patients or their personal representatives. These invoices contained patients' names, billing addresses, account balances, and some invoices included the names and dosage amounts of medications provided by the covered entity (CE), Saliba Extended Care Pharmacy, to the patient. Approximately 6,599 individuals were affected by the breach. The CE discovered the inadvertent emailing on January 16, 2017, recalled the email sent to all recipients and reached out to the three recipients who confirmed they opened the email message and requested that the recipients permanently delete the email. After the incident, the CE restricted workforce access to the folder containing patient invoices, retrained billing staff on proper methods for accessing and emailing patient invoices and on its HIPAA policies and procedures, and sanctioned the employee who sent the email. The CE also developed a secure online portal through which patients can directly retrieve their monthly invoices. The CE provided breach notification to HHS, affected individuals, and media, as well as substitute notification. OCR provided the CE with technical assistance regarding the risk analysis and risk management provisions of the HIPAA Security Rule.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.