DIGNITY HEALTH
bd_172bbf61ccaa8a49 · schema v1 · pii pii-v1
Full breach record for DIGNITY HEALTH →During a mass emailing in April 2018, Dignity Health (CA) used an email list incorrectly formatted by its business associate, causing 55,947 individuals to receive an email intended for another individual. Exposed PHI included first name, last name, and physician name. The CE notified HHS, affected individuals, and the media. OCR obtained assurances of voluntary corrective actions: elimination of personalized greetings in mass communications, updated email policies, and a designated approver for all mass communication projects. Breach submitted to HHS on 2018-05-31. Breached information located on Email.
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_4702f77eeeb9ec81Montana State AGfiled 2018-06-13(13d gap)Verified
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- May 31, 2018
- Raw hash
- 5f50075f2ca6f58e966721ee67e33d0de2cccd633bfea83aac250bfb8efa80dd
Source filing
Reporting entity
- Name
- DIGNITY HEALTHnorm: dignity health
- Domain
- dignityhealth.org
- Industry
- Health Care Services
Victim entity
- Name
- DIGNITY HEALTHnorm: dignity health
- Domain
- dignityhealth.org
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 55,947
- Data types
- HEALTH_BASICIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1566 Phishing
- Threat actor
- Partner
- Regulator citations
- HHS OCR notified; OCR obtained assurances of voluntary corrective actions
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.