DIGNITY HEALTH
bd_172bbf61ccaa8a49 · schema v1 · pii pii-v1
Full breach record for DIGNITY HEALTH →During a mass emailing in April 2018, Dignity Health (CA) used an email list incorrectly formatted by its business associate, causing 55,947 individuals to receive an email intended for another individual. Exposed PHI included first name, last name, and physician name. The CE notified HHS, affected individuals, and the media. OCR obtained assurances of voluntary corrective actions: elimination of personalized greetings in mass communications, updated email policies, and a designated approver for all mass communication projects. Breach submitted to HHS on 2018-05-31. Breached information located on Email.
J jump to incidentP pin to compareR raw source
Incident timeline
Apr 1, 2018
Begins
May 31, 2018
Filed
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- Montana State AGbd_4702f77eeeb9ec812018-06-13 · +13dVerified
Filing propagation · 2 filings · 2 states
View merged incident ↗Pattern: first filing May 31 (CA), last Jun 13 (MT) — a 13-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.