- State
- OR
- Covered entity type
- Healthcare Provider
- Individuals affected
- 5,327
- Business associate present
- No
- Type of breach
- Theft
- Location of breached information
- Desktop Computer, Paper/Films
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On October 13, 2015, the covered entity (CE), Northwest Primary Care Group, discovered that a former employee, prior to being terminated, had impermissibly accessed and downloaded information from a desktop computer within the facility. Local law enforcement notified the CE that the former employee had accessed and printed a fifty-two (52) page document that contained the protected health information of 5,327 individuals. The types of PHI contained in the document included the names of 5,327 patients, and one or more of the following: social security numbers, dates of birth, credit card and/or bank account information. The CE notified HHS, affected individuals, and the media pursuant to the Breach Notification Rule. It also offered one year of free credit monitoring to all affected individuals. Following the breach, the CE implemented technical safeguards, revised its HIPAA policies and procedures, and retrained workforce members. OCR obtained satisfactory assurances that the CE implemented the corrective actions noted above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.