- State
- CA
- Covered entity type
- Healthcare Provider
- Individuals affected
- 4,262
- Business associate present
- No
- Type of breach
- Theft
- Location of breached information
- Other
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
Napa Valley Dentistry (NVD), the covered entity (CE), discovered that an unencrypted server that contained electronic protected health information (ePHI) had been stolen from its offsite storage unit. The breach affected 4,262 individuals and the ePHI involved included names, dates of birth, social security numbers, addresses, and financial information. In response to the breach, NVD performed a risk analysis, executed a corresponding risk management plan, and implemented several updates to its policies and procedures. In response to OCR’s investigation, NVD provided additional training to the staff members pertaining to the HIPAA Privacy, Security, and Breach Notification Rules.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.