Back to the register

Sutter Medical Foundation

ArchivedSubmitted 09/11/2015
State
CA
Covered entity type
Healthcare Provider
Individuals affected
2,302
Business associate present
Yes
Type of breach
Unauthorized Access/Disclosure
Location of breached information
Email
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

Sutter Medical Foundation (SMF), the covered entity (CE), reported that Sutter Health discovered that a former employee of Sutter Connect, LLC, dba Sutter Physician Services (SPS) had retained copies of certain SPS information containing patient information. Sutter Health was alerted to this situation by the former employee’s relatives, who expressed concern that the former employee may have been involved in separate identity theft and/or unlawful check writing efforts. As a part of its investigation into the matter, Sutter Health determined that the former employee had separately emailed certain electronic documents to a personal email account. The emails included information on 2,302 individuals. The types of protected health information (PHI) involved included names, dates of birth, financial information, claims information, clinical information, and diagnosis/conditions. As a result of OCR’s investigation, SMF filed a separate breach report for the initial incident involving the retention of copies of paper records. Additionally, SMF re-trained its staff on how to safeguard PHI.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.