San Francisco Department of Public Health
ent_d5bf9d523b558433011269dc
Disclosures
5
HHS OCR · State AG · 1 jurisdiction
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
1,174
nationwide · HHS OCR CA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- San Francisco Department of Public Health
- Normalized
- san francisco department of public health— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (5)newest first
- CALIFORNIAHHS OCRas victim2019-12-16
San Francisco Department of Public Health - Zuckerberg SF General Hospital reported to HHS on 2019-12-16 an Improper Disposal affecting 1174 individuals. Breached information located on Paper/Films. An employee improperly disposed of documents containing PHI including names, birthdates, clinical, and treatment information.
- CALIFORNIAHHS OCRas victim2019-10-03
The San Francisco Department of Public Health reported that its business associate, Alluma, experienced a computer error that resulted in mislabeled letters containing protected health information being sent to incorrect recipients. The incident, affecting 622 individuals, involved paper records and films with demographic information. In response, the entity investigated the issue, implemented new technical safeguards, and updated its quality control process for renewal notices.
- California State AGas victim2019-10-03
San Francisco Department of Public Health notified residents that a third-party vendor, Alluma, mistakenly sent letters containing personal information (name, address, application ID, participant ID, medical home, renewal date) to wrong addresses between November 2018 and August 2019 due to a computer error. The incident was discovered on August 8, 2019. Corrected letters were sent. No SSN or DOB was involved.
- CALIFORNIAHHS OCRas victim2018-06-25
San Francisco Department of Public Health reported to HHS on 2018-06-25 a Unauthorized Access/Disclosure affecting 900 individuals. Breached information located on Network Server. An individual gained unauthorized access to a business associate's network server and downloaded PHI (names, DOB, diagnoses) to an external hard drive. Notification was provided on May 11, 2018, following a law enforcement delay.
- California State AGas victim2018-05-11
San Francisco Department of Public Health notified patients that a former employee of third-party vendor Nuance Communications accessed patient medical records between Nov 20 and Dec 9, 2017. The incident was discovered on Dec 22, 2017. Affected data included names, DOB, medical record numbers, and clinical information. No SSNs or financial data were involved. Notification was delayed per FBI/DOJ request.