Back to the register

Skin and Cancer Center of Arizona

ArchivedSubmitted 09/21/2015
State
AZ
Covered entity type
Healthcare Provider
Individuals affected
3,311
Business associate present
No
Type of breach
Unauthorized Access/Disclosure
Location of breached information
Paper/Films
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

OCR investigated the covered entity (CE), Skin and Cancer Center of Arizona, after the CE reported a breach of 3,311 individuals’ protected health information (PHI) that it learned about on July 29, 2015. A former employee possessed PHI from the CE's office, which was further disclosed to the former employee’s new employer after her employment ended on March 18, 2015. The breach affected patients' names, dates of birth, telephone numbers, insurance company names, and reasons for appointment(s). The CE provided breach notification to HHS, affected individuals, and the media. In response to OCR’s contact in this matter, the CE retrieved all the breached PHI, ensured the former employee and the former employee’s new employer no longer had copies of the PHI, and that they ceased from further use or disclosure of the PHI. The CE also took steps to retrain workforce members, implemented regular workforce HIPAA reminders, and increased the physical security of its employee workspace. OCR obtained documentation that the CE implemented these corrective actions.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.