Saliba's Extended Care Pharmacy
Disclosed Mar 3, 20179 years ago6,599 affectedConfirmed
On January 12, 2017, an employee inadvertently emailed an attachment containing patient invoices for December 2016 to six current patients or their personal representatives. These invoices contained patients' names, billing addresses, account balances, and some invoices included the names and dosage amounts of medications provided by the covered entity (CE), Saliba Extended Care Pharmacy, to the patient. Approximately 6,599 individuals were affected by the breach. The CE discovered the inadvertent emailing on January 16, 2017, recalled the email sent to all recipients and reached out to the three recipients who confirmed they opened the email message and requested that the recipients permanently delete the email. After the incident, the CE restricted workforce access to the folder containing patient invoices, retrained billing staff on proper methods for accessing and emailing patient invoices and on its HIPAA policies and procedures, and sanctioned the employee who sent the email. The CE also developed a secure online portal through which patients can directly retrieve their monthly invoices. The CE provided breach notification to HHS, affected individuals, and media, as well as s
What is known
| People affected | 6,599 (as reported to HHS) |
|---|---|
| Disclosed | Mar 3, 2017 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Saliba's Extended Care Pharmacy (Healthcare Provider, AZ)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Mar 3, 2017 | 6,599 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.