St. Joseph's Hospital and Medical Center
Disclosed Feb 13, 20179 years ago623 affectedConfirmed
A part-time clinical employee of the covered entity (CE), St. Joseph’s Hospital and Medical Center, a Dignity Health facility in Arizona, impermissibly accessed the protected health information (PHI) of patients. The breach affected the full names, dates of birth, diagnoses/conditions, and medications of approximately 623 individuals. The CE provided breach notification to HHS, affected individuals, and the media, and also provided substitute notice. Following the breach, the CE sanctioned the employee responsible for the incident and reported the employee to his licensing board. In response to the incident, the CE conducted a thorough audit of the employee’s medical record access during the entire term of his employment. OCE obtained assurances that the CE implemented the corrective actions listed above. In this case, the sanction included termination of employment.
What is known
| People affected | 623 (as reported to HHS) |
|---|---|
| Disclosed | Feb 13, 2017 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): St. Joseph's Hospital and Medical Center (Healthcare Provider, AZ)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Feb 13, 2017 | 623 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.