- State
- CA
- Covered entity type
- Healthcare Provider
- Individuals affected
- 5,499
- Business associate present
- No
- Type of breach
- Theft
- Location of breached information
- Other Portable Electronic Device
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
A workforce member’s car was broken into resulting in the theft and loss of two unencrypted flash drives containing the protected health information (PHI) of 5,499 individuals. Types of PHI involved in the breach included names, dates of birth, diagnoses/treatment information, and insurance information, including some Medicare numbers. The CE provided breach notification to HHS, affected individuals, and the media, and provided credit monitoring and identity theft protection for the affected individuals. In response to the breach, the CE sanctioned and retrained the workforce member involved with the breach who was not following the CE's policies and procedures and retrained other workforce members on its HIPAA security procedures. The CE also implemented a USB encryption lockdown project which enhanced the CE's technical safeguards. OCR’s investigation resulted in improved HIPAA practices at the covered entity.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.