- State
- CA
- Covered entity type
- Healthcare Provider
- Individuals affected
- 2,302
- Business associate present
- Yes
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
Sutter Medical Foundation (SMF), the covered entity (CE), reported that Sutter Health discovered that a former employee of Sutter Connect, LLC, dba Sutter Physician Services (SPS) had retained copies of certain SPS information containing patient information. Sutter Health was alerted to this situation by the former employee’s relatives, who expressed concern that the former employee may have been involved in separate identity theft and/or unlawful check writing efforts. As a part of its investigation into the matter, Sutter Health determined that the former employee had separately emailed certain electronic documents to a personal email account. The emails included information on 2,302 individuals. The types of protected health information (PHI) involved included names, dates of birth, financial information, claims information, clinical information, and diagnosis/conditions. As a result of OCR’s investigation, SMF filed a separate breach report for the initial incident involving the retention of copies of paper records. Additionally, SMF re-trained its staff on how to safeguard PHI.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.