Regional Center of the East Bay
Disclosed Jul 9, 20251 year ago689 affectedConfirmed
The covered entity (CE), Regional Center of the East Bay, reported that an employee sent an email containing the protected health information (PHI) of 689 individuals to an unintended recipient. The PHI involved included names, dates of birth, and other identifiers. The CE notified HHS, the affected individuals, and the media regarding the breach. In response to the breach the CE sent an email reminder to all employees regarding its HIPAA compliance policies and procedures and provided written counseling to the affected employee.
What is known
| People affected | 689 (as reported to HHS) |
|---|---|
| Disclosed | Jul 9, 2025 |
| Happened | Jun 24, 2025 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Nonprofit · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| California Attorney General breach notice: Regional Center of the East Bayoag.ca.gov · Official notice | Official notice |
| HHS OCR breach report (archive, resolved): Regional Center of the East Bay (Healthcare Provider, CA)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| California AGresidents of CA | Jul 9, 2025 | |
| HHS archivetotal | Jul 9, 2025 | 689 |
History of this record
- 2026-09-25 · attack: unknown to insider · backfill source
- 2026-09-25 · data_types: [] to ["names","health"] · backfill source
- 2026-09-25 · records_basis: empty to hhs · backfill source
- 2026-09-25 · records: empty to 689 · backfill source
- 2026-09-25 · summary: empty to The covered entity (CE), Regional Center of the East Bay, reported that an employee sent an email containing the protected health information (PHI) of 689 individuals to an unintended recipient. The PHI involved included names, dates of bir · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.