The covered entity (CE), Guardant Health, Inc., reported that a workforce member inadvertently made the protected health information (PHI) of 9,309 individuals viewable over the Internet. The PHI involved included names, ages, medical record and identification numbers, and treatment information. The CE notified HHS and the affected individuals. In response to the breach, the CE sanctioned its workforce member and implemented additional technical safeguards to better protect its PHI. OCR provided the CE with technical assistance regarding the HIPAA Breach Notification Rule.
2026-09-25 · attack: unknown to insider · backfill source
2026-09-25 · data_types: [] to ["names","health"] · backfill source
2026-09-25 · records_basis: empty to hhs · backfill source
2026-09-25 · records: empty to 9309 · backfill source
2026-09-25 · disclosed: 2024-05-03 to 2024-04-26 · backfill source
2026-09-25 · summary: empty to The covered entity (CE), Guardant Health, Inc., reported that a workforce member inadvertently made the protected health information (PHI) of 9,309 individuals viewable over the Internet. The PHI involved included names, ages, medical recor · backfill source
2026-09-25 · source: empty to https://ago.vermont.gov/document/2024-05-03-guardant-health-data-breach-notice-consumers · backfill source