- State
- WA
- Covered entity type
- Healthcare Provider
- Individuals affected
- 504
- Business associate present
- No
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- Desktop Computer, Paper/Films
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
An employee of the covered entity (CE), the Kalispel Tribe of Indians, Camas Center Clinic, gave an “on-call” temporary administrative assistant at the CE’s facility, who had not yet been trained in HIPAA, the employee’s personal login and password information. The assistant used the login/password information to access electronic protected health information (ePHI) on the employee’s computer. When the information technology department learned of this impermissible access, it quickly disabled the employee’s login information, as the ePHI had been shared in violation of the CE’s policies. In addition to ePHI, the assistant also accessed paper PHI. The breach affected approximately 504 individuals and the types of PHI and ePHI involved included demographic, financial, and clinical information. The CE provided breach notification to the affected individuals, the media, and HHS. The CE sanctioned the employee pursuant to its policies for impermissibly sharing the login/password information and retrained its workforce members on HIPAA. OCR obtained assurances that the CE implemented the corrective action measures described.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.