Catalina Post-Acute Care and Rehabilitation
Disclosed Feb 2, 20179 years ago2,953 affectedConfirmed
Catalina Post-Acute Care and Rehabilitation (CPACR), discovered that some paper documents containing protected health inform information (PHI) had been left unattended and accessible to the public for approximately six months. The breach affected approximately 2,953 individuals. The PHI involved includes names, dates of birth, addresses, social security numbers, drivers’ license numbers, claims information, clinical information, and financial information. CPACR provided free credit monitoring to all affected individuals; implemented physical, administrative, and security safeguards in response to the breach incident; and drafted new policies and procedures; and re-trained its workforce.
What is known
| People affected | 2,953 (as reported to HHS) |
|---|---|
| Disclosed | Feb 2, 2017 |
| Attack | Lost or stolen device |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Catalina Post-Acute Care and Rehabilitation (Healthcare Provider, AZ)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Feb 2, 2017 | 2,953 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.
Everything about Catalina Post-Acute Care and Rehabilitation