Back to the register
CHI Franciscan Health, St. Clare Hospital and St. Joseph Medical Center
ArchivedSubmitted 09/16/2016
- State
- WA
- Covered entity type
- Healthcare Provider
- Individuals affected
- 2,818
- Business associate present
- No
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- Electronic Medical Record
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On July 22, 2016, CHI Franciscan Health, the covered entity (CE), learned that an employee-physician had been impermissibly accessing St. Clare Hospital and St. Joseph Medical Center patient information since July 1, 2015, to try to expand the physician’s client base. Approximately 2,818 individuals were affected by this breach incident. The types of electronic protected health information (ePHI) involved included clinical information, such as diagnoses, conditions, lab results, medications, and other treatment information. The CE provided breach notification to affected individuals, the media and HHS, and also posted information about the breach on its website. The CE created a call center for patients and other concerned individuals, so that such individuals could get up-to-date information on the breach incident and receive assistance as needed. In addition, the CE sanctioned the responsible physician in accordance with its HIPAA sanctions policy and retrained its workforce members on HIPAA, which included a session on “Acceptable Uses and Disclosures of PHI for Physicians.” OCR obtained assurances that the CE implemented the corrective actions described above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.