Skip to content

Graybill Medical Group

Disclosed Oct 15, 201411 years ago1,863 affectedConfirmed

Official notice

A group of x-rays of poor quality were placed in the covered entity’s (CE) trash container for destruction. The cleaning personnel mistook the x-rays for regular trash and disposed of them in the usual manner. The CE, Graybill Medical Center, initiated an immediate search but the x-rays had already been taken to the landfill. The breach occurred on September 9, 2014, and affected 1,863 patients. The protected health information (PHI) contained patients’ names, addresses, dates of birth, physician/medical provider information, and, possibly, images of some areas of patients’ bodies. The CE provided breach notification to HHS, affected individuals and the media, and offered credit monitoring. Following the breach, the CE improved safeguards by ordering locked bins for x-rays that are to be destroyed, ordering covers for the PHI being transported, and implementing procedures requiring x-rays to be recycled weekly so as to more easily distinguish them from regular trash. The CE also retrained its workforce on its HIPAA policies. OCR obtained assurances that the CE implemented the corrective actions listed.

What is known

People affected1,863 (as reported to HHS)
DisclosedOct 15, 2014
AttackLost or stolen device
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
HHS OCR breach report (archive, resolved): Graybill Medical Group (Healthcare Provider, CA)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalOct 15, 20141,863
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Graybill Medical Group

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.