Skip to content

CHI Franciscan Health, St. Clare Hospital and St. Joseph Medical Center

Disclosed Sep 16, 201610 years ago2,818 affectedConfirmed

Official notice

On July 22, 2016, CHI Franciscan Health, the covered entity (CE), learned that an employee-physician had been impermissibly accessing St. Clare Hospital and St. Joseph Medical Center patient information since July 1, 2015, to try to expand the physician’s client base. Approximately 2,818 individuals were affected by this breach incident. The types of electronic protected health information (ePHI) involved included clinical information, such as diagnoses, conditions, lab results, medications, and other treatment information. The CE provided breach notification to affected individuals, the media and HHS, and also posted information about the breach on its website. The CE created a call center for patients and other concerned individuals, so that such individuals could get up-to-date information on the breach incident and receive assistance as needed. In addition, the CE sanctioned the responsible physician in accordance with its HIPAA sanctions policy and retrained its workforce members on HIPAA, which included a session on “Acceptable Uses and Disclosures of PHI for Physicians.” OCR obtained assurances that the CE implemented the corrective actions described above.

What is known

People affected2,818 (as reported to HHS)
DisclosedSep 16, 2016
AttackInsider
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
HHS archivetotalSep 16, 20162,818
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about CHI Franciscan Health, St. Clare Hospital and St. Joseph Medical Center

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.