Sunshine Behavioral Health Group
Disclosed Dec 2, 20196 years ago3,638 affectedConfirmed
The business associate (BA), Sunshine Behavioral Health Group, LLC, reported that a cloud-based system used to store certain patient records for its health care providers was improperly set up, and therefore subject to unauthorized access. This breach affected the electronic protected health information (ePHI) of 3,638 individuals. The ePHI involved included names, addresses, Social security numbers, dates of birth, email addresses, telephone numbers, health insurance and claims information, financial information, diagnoses, treatment information, and lab results. The BA notified HHS, affected individuals, the media, and provided complimentary credit monitoring services. Following the breach, the BA revised its HIPAA policies and procedures and retrained its staff. OCR obtained assurances that the CE implemented the corrective actions noted.
What is known
| People affected | 3,638 (as reported to HHS) |
|---|---|
| Disclosed | Dec 2, 2019 |
| Happened | Mar 1, 2017 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| California Attorney General breach notice: Sunshine Behavioral Health Groupoag.ca.gov · Official notice | Official notice |
| HHS OCR breach report (archive, resolved): Sunshine Behavioral Health Group (Business Associate, CA)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Dec 2, 2019 | 3,638 |
| California AGresidents of CA | Jan 21, 2020 |
History of this record
- 2026-09-25 · attack: unknown to insider · backfill source
- 2026-09-25 · data_types: [] to ["names","health"] · backfill source
- 2026-09-25 · records_basis: empty to hhs · backfill source
- 2026-09-25 · records: empty to 3638 · backfill source
- 2026-09-25 · disclosed: 2020-01-21 to 2019-12-02 · backfill source
- 2026-09-25 · summary: empty to The business associate (BA), Sunshine Behavioral Health Group, LLC, reported that a cloud-based system used to store certain patient records for its health care providers was improperly set up, and therefore subject to unauthorized access. · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.