- State
- CA
- Covered entity type
- Healthcare Provider
- Individuals affected
- 9,000
- Business associate present
- No
- Type of breach
- Theft
- Location of breached information
- Desktop Computer, Laptop
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
The covered entity (CE) reported to OCR that its office was burglarized, and a laptop and desktop computer, as well as its backup data were stolen. The computers contained the protected health information (PHI) of approximately 9,000 individuals. The PHI involved in the breach included names, addresses, dates of birth, some social security numbers, and claims information. The CE provided breach notification to HHS, affected individuals, and the media. Following the breach, the CE strengthened its physical safeguards, encrypted its computers, and began storing its backup data at an off-site encrypted server. OCR’s investigation resulted in the CE undertaking a new risk analysis and risk management plan and enhancing its practices for safeguarding PHI and ePHI.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.