Tulare County Health & Human Services Agency
Disclosed Apr 2, 201511 years ago845 affectedConfirmed
The covered entity (CE) reported a breach of 845 individuals’ electronic protected health information (e-PHI), as a result of a workforce member e-mailing information regarding logging into CE’s health care portal, without blind copying the patients, and encrypting the e-mails. This action, or lack thereof, left every patient’s e-mail address exposed. The CE provided breach notification to HHS, affected individuals, and the media. Following the breach, the CE improved safeguards by changing and strengthening password requirements, disabling all patients’ health portal accounts, and implementing new technical safeguards. In addition, the CE required all affected patients to re-register with its online portal, and revised and implemented new policies and procedures. The CE sanctioned the workforce members involved and re-trained the entire workforce. OCR provided technical assistance regarding the HIPAA Security Rule and obtained documented assurances that the CE implemented the corrective actions listed above.
What is known
| People affected | 845 (as reported to HHS) |
|---|---|
| Disclosed | Apr 2, 2015 |
| Happened | Mar 19, 2015 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| California Attorney General breach notice: Tulare County Health & Human Services Agencyoag.ca.gov · Official notice | Official notice |
| HHS OCR breach report (archive, resolved): Tulare County Health & Human Services Agency (Healthcare Provider, CA)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Apr 2, 2015 | 845 |
| California AGresidents of CA | Apr 6, 2015 |
History of this record
- 2026-09-25 · attack: unknown to insider · backfill source
- 2026-09-25 · data_types: [] to ["names","health"] · backfill source
- 2026-09-25 · records_basis: empty to hhs · backfill source
- 2026-09-25 · records: empty to 845 · backfill source
- 2026-09-25 · disclosed: 2015-04-06 to 2015-04-02 · backfill source
- 2026-09-25 · summary: empty to The covered entity (CE) reported a breach of 845 individuals’ electronic protected health information (e-PHI), as a result of a workforce member e-mailing information regarding logging into CE’s health care portal, without blind copying the · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.
Everything about Tulare County Health & Human Services Agency