Family Health Centers of San Diego
Disclosed May 12, 20264 months ago523 affectedConfirmed
The covered entity (CE), Family Health Centers of San Diego, reported that an employee forwarded emails containing the protected health information (PHI) of 523 individuals to her personal email account without approval or authorization. The PHI involved included clinical and demographic information. The CE notified HHS, the media, and the affected individuals. In response to the breach, the CE implemented additional administrative, technical, and security safeguards to better protect its PHI.
What is known
| People affected | 523 (as reported to HHS) |
|---|---|
| Disclosed | May 12, 2026 |
| Happened | Dec 15, 2021 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| California Attorney General breach notice: Family Health Centers of San Diegooag.ca.gov · Official notice | Official notice |
| HHS OCR breach report (archive, resolved): Family Health Centers of San Diego (Healthcare Provider, CA)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| California AGresidents of CA | May 12 | |
| HHS archivetotal | May 12 | 523 |
History of this record
- 2026-09-25 · attack: unknown to insider · backfill source
- 2026-09-25 · data_types: [] to ["names","health"] · backfill source
- 2026-09-25 · records_basis: empty to hhs · backfill source
- 2026-09-25 · records: empty to 523 · backfill source
- 2026-09-25 · summary: empty to The covered entity (CE), Family Health Centers of San Diego, reported that an employee forwarded emails containing the protected health information (PHI) of 523 individuals to her personal email account without approval or authorization. Th · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.