Mercy Medical Center Redding
Disclosed Jun 24, 201610 years ago520 affectedConfirmed
An employee of a business associate (BA), naviHealth, provided services to the covered entity’s (CE) patients using an assumed name and nursing license from June 1, 2015, to May 13, 2016, and accessed protected health information (PHI) in the course of employment. The breach affected 520 individuals who were patients of the CE's Redding facility and a total of 1,253 Dignity Health patients in California and Nevada. The types of PHI involved in the breach included full names, addresses, dates of birth, social security numbers, claims information, diagnoses/conditions, lab results, and medications. The CE provided breach notification to HHS, affected individuals, and the media and also provided substitute notice. OCR reviewed the BA agreement in place between the CE and BA and obtained assurances that the CE implemented the corrective actions listed above. In response to the breach, the BA sanctioned the responsible employee, terminated the employee’s access to all PHI, and contacted law enforcement to report the incident. The BA also reviewed recorded calls made by the employee and PHI accessed by the employee to ensure that PHI was accessed to provide patients with services accordi
What is known
| People affected | 520 (as reported to HHS) |
|---|---|
| Disclosed | Jun 24, 2016 |
| Happened | Jun 1, 2016 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| California Attorney General breach notice: Mercy Medical Center Reddingoag.ca.gov · Official notice | Official notice |
| HHS OCR breach report (archive, resolved): Mercy Medical Center Redding (Healthcare Provider, CA)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| California AGresidents of CA | Jun 24, 2016 | |
| HHS archivetotal | Jun 29, 2016 | 520 |
History of this record
- 2026-09-25 · attack: unknown to insider · backfill source
- 2026-09-25 · data_types: [] to ["names","health"] · backfill source
- 2026-09-25 · records_basis: empty to hhs · backfill source
- 2026-09-25 · records: empty to 520 · backfill source
- 2026-09-25 · summary: empty to An employee of a business associate (BA), naviHealth, provided services to the covered entity’s (CE) patients using an assumed name and nursing license from June 1, 2015, to May 13, 2016, and accessed protected health information (PHI) in t · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.