Sutter Medical Foundation (SMF), the covered entity (CE), reported that Sutter Health discovered that a former employee of Sutter Connect, LLC, dba Sutter Physician Services (SPS) had retained copies of certain SPS information containing patient information. Sutter Health was alerted to this situation by the former employee’s relatives, who expressed concern that the former employee may have been involved in separate identity theft and/or unlawful check writing efforts. As a part of its investigation into the matter, Sutter Health determined that the former employee had separately emailed certain electronic documents to a personal email account. The emails included information on 2,302 individuals. The types of protected health information (PHI) involved included names, dates of birth, financial information, claims information, clinical information, and diagnosis/conditions. As a result of OCR’s investigation, SMF filed a separate breach report for the initial incident involving the retention of copies of paper records. Additionally, SMF re-trained its staff on how to safeguard PHI.
2026-09-25 · attack: unknown to insider · backfill source
2026-09-25 · data_types: [] to ["names","health"] · backfill source
2026-09-25 · records_basis: empty to hhs · backfill source
2026-09-25 · records: empty to 2302 · backfill source
2026-09-25 · summary: empty to Sutter Medical Foundation (SMF), the covered entity (CE), reported that Sutter Health discovered that a former employee of Sutter Connect, LLC, dba Sutter Physician Services (SPS) had retained copies of certain SPS information containing pa · backfill source