Sutter Valley Medical Foundation
Disclosed Nov 22, 20178 years ago1,303 affectedConfirmed
Sutter Medical Foundation, the covered entity (CE), reported that an encrypted laptop and a binder of paper documents were stolen from an employee’s locked vehicle. The CE determined that the subsequently recovered paper documents were intact. The protected health information (PHI) exposed included the names, dates of birth, ages, medical record numbers, primary care physicians, treating providers’ names, appointment times, visit types, and/or any needed accommodations of 613 individuals. The CE notified prominent media outlets and posted a copy of the press release on its website. Following the breach, the CE sanctioned the responsible workforce member, offered affected individuals one year of identity theft protection, and retrained its workforce members. OCR obtained assurances that the CE implemented the corrective actions listed above.
What is known
| People affected | 1,303 (as reported to HHS) |
|---|---|
| Disclosed | Nov 22, 2017 |
| Attack | Lost or stolen device |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Sutter Valley Medical Foundation (Healthcare Provider, CA)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Nov 22, 2017 | 1,303 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.