- State
- CA
- Covered entity type
- Healthcare Provider
- Individuals affected
- 4,500,000
- Business associate present
- No
- Type of breach
- Hacking/IT Incident
- Location of breached information
- Network Server
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
A hacker accessed parts of the covered entity’s (CE) computer network that contained the clinical and demographic information of approximately 4,500,000 individuals. The CE reported the incident to the Federal Bureau of Investigation and conducted a forensic analysis of the incident. The CE provided breach notification to HHS, affected individuals, and the media, and also posted substitute notice. Following the breach, the CE implemented technical and administrative safeguards designed to help detect and contain any future cyber-attacks. OCR obtained assurances that the CE implemented the corrective actions above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.