- State
- CA
- Covered entity type
- Healthcare Provider
- Individuals affected
- 2,500
- Business associate present
- No
- Type of breach
- Theft
- Location of breached information
- Other
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
A physician formerly affiliated with a business associate, the University of California, San Francisco (UCSF) removed patients’ electronic protected health information (ePHI) from the covered entity (CE), San Francisco General Hospital and Trauma Center , without authorization. The CE estimated that approximately 2,500 individuals were affected by the breach. The types of ePHI affected included patients’ names, surgical notes, consultation notes, and radiologic films. The CE provided breach notification to affected individuals, the media, and HHS. In response the breach, the CE implemented new HIPAA Privacy and Security policies and procedures, including a new/updated Security Rule Risk Management Plan and Security Risk Analysis, new technological safeguards, periodic technical and non-technical evaluations, and trained and retained workforce members . OCR obtained assurances that the CE implemented the corrective actions noted above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.