Skip to content

Shutterfly

Disclosed Dec 18, 20214 years ago52,777 affectedConfirmed

Official notice

The business associate (BA), Shutterfly, LLC, reported that an employee mailed the protected health information (PHI) of 2,641 individuals to the wrong recipients. The PHI involved included names, addresses, diagnoses, health insurance information, and claims and other treatment information. The BA notified HHS and the affected individuals. In response to the breach, the BA implemented additional technical safeguards, revised its policies and procedures, and retrained its employees.

What is known

People affected52,777 (as reported by the organization)
DisclosedDec 18, 2021
DiscoveredDec 13, 2021
HappenedDec 3, 2021
AttackRansomware
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
California Attorney General breach notice: Shutterflyoag.ca.gov · Official notice
Washington Attorney General breach notice: Shutterflyatg.wa.gov · Official notice
Oregon DOJ breach notice: Shutterflyjustice.oregon.gov · Official notice
Indiana Attorney General 2022 data breach report: Shutterflyin.gov · Official notice
HHS OCR breach report (archive, resolved): Shutterfly (Business Associate, CA)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
Indiana AGresidents of INDec 18, 20211,678
California AGresidents of CAMar 23, 2022
HHS archivetotalMay 3, 20222,641
Washington AGresidents of WAMay 26, 20221,273
Oregon DOJresidents of ORMay 26, 202252,777
California AGresidents of CAJun 2, 2022

Other breaches at Shutterfly

BreachAffected
Disclosed Mar 27, 2018Mar 27, 20188 years ago9,428
Disclosed Nov 26, 2014Nov 26, 201411 years agoUnknown
History of this record
  • 2026-09-25 · sector: other to health · backfill source
  • 2026-09-25 · data_types: [] to ["names","health"] · backfill source
  • 2026-09-25 · summary: empty to The business associate (BA), Shutterfly, LLC, reported that an employee mailed the protected health information (PHI) of 2,641 individuals to the wrong recipients. The PHI involved included names, addresses, diagnoses, health insurance info · backfill source
  • 2026-09-25 · records_basis: empty to organization · backfill source
  • 2026-09-25 · records: empty to 52777 · backfill source
  • 2026-09-25 · disclosed: 2022-03-23 to 2021-12-18 · backfill source
  • 2026-09-25 · attack: unknown to ransomware · backfill source
  • 2026-09-25 · discovered: empty to 2021-12-13 · backfill source
  • 2026-09-25 · disclosed: 2022-06-02 to 2022-03-23 · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.

Everything about Shutterfly

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.