Back to the register

Graybill Medical Group

ArchivedSubmitted 10/15/2014
State
CA
Covered entity type
Healthcare Provider
Individuals affected
1,863
Business associate present
No
Type of breach
Theft
Location of breached information
Other
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

A group of x-rays of poor quality were placed in the covered entity’s (CE) trash container for destruction. The cleaning personnel mistook the x-rays for regular trash and disposed of them in the usual manner. The CE, Graybill Medical Center, initiated an immediate search but the x-rays had already been taken to the landfill. The breach occurred on September 9, 2014, and affected 1,863 patients. The protected health information (PHI) contained patients’ names, addresses, dates of birth, physician/medical provider information, and, possibly, images of some areas of patients’ bodies. The CE provided breach notification to HHS, affected individuals and the media, and offered credit monitoring. Following the breach, the CE improved safeguards by ordering locked bins for x-rays that are to be destroyed, ordering covers for the PHI being transported, and implementing procedures requiring x-rays to be recycled weekly so as to more easily distinguish them from regular trash. The CE also retrained its workforce on its HIPAA policies. OCR obtained assurances that the CE implemented the corrective actions listed.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.