Northwest Primary Care Group
Disclosed Dec 11, 201510 years ago5,327 affectedConfirmed
On October 13, 2015, the covered entity (CE), Northwest Primary Care Group, discovered that a former employee, prior to being terminated, had impermissibly accessed and downloaded information from a desktop computer within the facility. Local law enforcement notified the CE that the former employee had accessed and printed a fifty-two (52) page document that contained the protected health information of 5,327 individuals. The types of PHI contained in the document included the names of 5,327 patients, and one or more of the following: social security numbers, dates of birth, credit card and/or bank account information. The CE notified HHS, affected individuals, and the media pursuant to the Breach Notification Rule. It also offered one year of free credit monitoring to all affected individuals. Following the breach, the CE implemented technical safeguards, revised its HIPAA policies and procedures, and retrained workforce members. OCR obtained satisfactory assurances that the CE implemented the corrective actions noted above.
What is known
| People affected | 5,327 (as reported to HHS) |
|---|---|
| Disclosed | Dec 11, 2015 |
| Attack | Lost or stolen device |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Northwest Primary Care Group (Healthcare Provider, OR)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Dec 11, 2015 | 5,327 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.