San Francisco Department of Public Health
ent_d5bf9d523b558433011269dc
Disclosures
4
HHS OCR · State AG · 2 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
900
nationwide · HHS OCR CA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- San Francisco Department of Public Health
- Normalized
- san francisco department of public health— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (4)newest first
- FEDERALHHS OCRas victim2019-10-03
The San Francisco Department of Public Health reported that its business associate, Alluma, experienced a computer error that resulted in mislabeled letters containing protected health information being sent to incorrect recipients. The incident, affecting 622 individuals, involved paper records and films with demographic information. In response, the entity investigated the issue, implemented new technical safeguards, and updated its quality control process for renewal notices.
- 🐻California State AGas victim2019-10-03
San Francisco Department of Public Health (SFDPH) disclosed a data breach involving its vendor, Alluma. Between November 2018 and August 2019, enrollment letters for Healthy San Francisco participants were mailed to incorrect addresses due to a computer error. Affected data included names, addresses, application/participant IDs, and medical home information. No SSN or DOB was included. SFDPH issued notifications on September 27, 2019, and is reviewing vendor privacy protections.
- CALIFORNIAHHS OCRas victim2018-06-25
San Francisco Department of Public Health reported to HHS on 2018-06-25 a Unauthorized Access/Disclosure affecting 900 individuals. Breached information located on Network Server. An individual gained unauthorized access to a business associate's network server and downloaded PHI (names, DOB, diagnoses) to an external hard drive. Notification was provided on May 11, 2018, following a law enforcement delay.
- 🐻California State AGas victim2018-05-11
San Francisco Department of Public Health (SFDPH) notified patients of a data breach involving third-party vendor Nuance Communications. An unauthorized former Nuance employee accessed patient records between November 20 and December 9, 2017. The breach exposed PHI including names, dates of birth, and medical records, but excluded SSNs or financial data. Law enforcement delayed notification during a criminal investigation. Nuance took the system offline immediately upon discovery.