Skip to content

RoxSan Pharmacy

Disclosed Mar 12, 20188 years ago1,049 affectedConfirmed

Official notice

On March 12, 2018, RoxSan Pharmacy, Inc., the covered entity (CE), reported to OCR that an impermissible disclosure of electronic protected health information (ePHI) occurred on January 20, 2015, when an employee of the CE emailed a spreadsheet containing ePHI to an attorney representing an employee of a business associate. The spreadsheet contained the ePHI of approximately 1,049 individuals. The ePHI included patient information, such as insurance information, prescription information, and physician names. The CE determined that the disclosure was impermissible because it was not made for the purposes of treatment, payment, or health care operations. The CE provided notice to HHS, individual notification, and media notification. OCR obtained documentation of the individual and media breach notifications. OCR also obtained documentation showing that the CE took the following steps in response to the breach and OCR’s corresponding investigation: (1) the CE updated its policies and procedures addressing the use and disclosure of PHI, safeguarding PHI, de-identifying PHI, and employee sanctions for noncompliance with HIPAA; (2) the employee responsible for the breach was sanctioned a

What is known

People affected1,049 (as reported to HHS)
DisclosedMar 12, 2018
AttackInsider
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
HHS OCR breach report (archive, resolved): RoxSan Pharmacy (Healthcare Provider, CA)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalMar 12, 20181,049
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about RoxSan Pharmacy

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.