Sierra View District Hospital
Disclosed Sep 20, 201313 years ago1,009 affectedConfirmed
A workforce member of the covered entity (CE), Sierra View Medical Center, impermissibly accessed an internal hospital roster covering different departments over a period of several days between July and August 2013, which potentially affected the electronic protected health information (ePHI) of approximately one thousand nine (1,009) individuals. The ePHI included patients' names, room numbers, treating physicians' information, diagnoses, and medical record data, including treatment notes. The CE provided breach notification to HHS, affected individuals, and the media. The CE investigated and determined that the employee had not used the information, despite impermissibly accessing it. The CE sanctioned the employee, implemented compliance actions to meet workforce security standards, including log-in monitoring. The CE also revised policies and procedures and conducted training on the security awareness standard. OCR provided substantive technical assistance and identified corrective actions that the CE must complete to comply with the Security Rule, which includes the following: conduct and monitor a comprehensive, enterprise-wide risk analysis, update and monitor its risk mana
What is known
| People affected | 1,009 (as reported to HHS) |
|---|---|
| Disclosed | Sep 20, 2013 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Sierra View District Hospital (Healthcare Provider, CA)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Sep 20, 2013 | 1,009 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.