Silverberg Surgical and Medical Group
Disclosed Sep 25, 201511 years ago857 affectedConfirmed
The covered entity (CE), Silverberg Surgical and Medical Group, reported that a business associate (BA), misconfigured its document scanning device allowing scanned records to be accessible via the Internet. The breach affected approximately 857 individuals. The protected health information (PHI) involved included names, addresses, dates of birth, phone numbers, email addresses, medical information, medical record numbers, health plan information, social security numbers, state license numbers, and full face photographic images. The CE provided breach notification to HHS, the affected individuals, and the media. The CE also revised its policies and procedures, retrained workforce members, provided all affected individuals with credit monitoring and identity theft consultation services, and implemented a dedicated call center to assist affected individuals.
What is known
| People affected | 857 (as reported to HHS) |
|---|---|
| Disclosed | Sep 25, 2015 |
| Happened | Sep 10, 2013 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| California Attorney General breach notice: Silverberg Surgical and Medical Groupoag.ca.gov · Official notice | Official notice |
| HHS OCR breach report (archive, resolved): Silverberg Surgical and Medical Group (Healthcare Provider, CA)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| California AGresidents of CA | Sep 25, 2015 | |
| HHS archivetotal | Sep 25, 2015 | 857 |
History of this record
- 2026-09-25 · attack: unknown to insider · backfill source
- 2026-09-25 · data_types: [] to ["names","health"] · backfill source
- 2026-09-25 · records_basis: empty to hhs · backfill source
- 2026-09-25 · records: empty to 857 · backfill source
- 2026-09-25 · summary: empty to The covered entity (CE), Silverberg Surgical and Medical Group, reported that a business associate (BA), misconfigured its document scanning device allowing scanned records to be accessible via the Internet. The breach affected approximatel · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.