RoxSan Pharmacy
Disclosed Mar 12, 20188 years ago1,049 affectedConfirmed
On March 12, 2018, RoxSan Pharmacy, Inc., the covered entity (CE), reported to OCR that an impermissible disclosure of electronic protected health information (ePHI) occurred on January 20, 2015, when an employee of the CE emailed a spreadsheet containing ePHI to an attorney representing an employee of a business associate. The spreadsheet contained the ePHI of approximately 1,049 individuals. The ePHI included patient information, such as insurance information, prescription information, and physician names. The CE determined that the disclosure was impermissible because it was not made for the purposes of treatment, payment, or health care operations. The CE provided notice to HHS, individual notification, and media notification. OCR obtained documentation of the individual and media breach notifications. OCR also obtained documentation showing that the CE took the following steps in response to the breach and OCR’s corresponding investigation: (1) the CE updated its policies and procedures addressing the use and disclosure of PHI, safeguarding PHI, de-identifying PHI, and employee sanctions for noncompliance with HIPAA; (2) the employee responsible for the breach was sanctioned a
What is known
| People affected | 1,049 (as reported to HHS) |
|---|---|
| Disclosed | Mar 12, 2018 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): RoxSan Pharmacy (Healthcare Provider, CA)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Mar 12, 2018 | 1,049 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.