Skip to content

Hillsides

Disclosed Dec 30, 201510 years ago502 affectedConfirmed

Official notice

A workforce member emailed documents containing personally identifiable information (PII) and protected health information (PHI) of patients and employees to a personal email address. The breach involved the PII and PHI of 970 individuals. The breached information included names, dates of birth, patient identification numbers, and health care provider information. Following the breach, the covered entity (CE), Hillsides, provided breach notification to HHS, affected individuals, and the media. It also sanctioned the workforce member involved, implemented safeguards, and retrained staff. OCR obtained assurances that the CE implemented the corrective actions listed above.

What is known

People affected502 (as reported to HHS)
DisclosedDec 30, 2015
HappenedOct 10, 2014
AttackInsider
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
California Attorney General breach notice: Hillsidesoag.ca.gov · Official notice
HHS OCR breach report (archive, resolved): Hillsides (Healthcare Provider, CA)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalDec 30, 2015502
California AGresidents of CADec 31, 2015
History of this record
  • 2026-09-25 · sector: other to health · backfill source
  • 2026-09-25 · attack: unknown to insider · backfill source
  • 2026-09-25 · data_types: [] to ["names","health"] · backfill source
  • 2026-09-25 · records_basis: empty to hhs · backfill source
  • 2026-09-25 · records: empty to 502 · backfill source
  • 2026-09-25 · disclosed: 2015-12-31 to 2015-12-30 · backfill source
  • 2026-09-25 · summary: empty to A workforce member emailed documents containing personally identifiable information (PII) and protected health information (PHI) of patients and employees to a personal email address. The breach involved the PII and PHI of 970 individuals. · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.

Everything about Hillsides

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.