White Blossom Care Center
Disclosed Jun 30, 20179 years ago800 affectedConfirmed
On June 30, 2017, the covered entity (CE), White Blossom Care Center reported that its former employees impermissibly accessed and copied its residents’ protected health information (PHI) while employed at the facility. The breached electronic PHI included names, dates of birth, social security numbers, telephone numbers, health insurance information, and medical record numbers. The CE provided breach notification to HHS, 791 affected individuals, and the media and posted substitute notice on its website. It also offered identity theft provision services to affected individuals. In response to the breach, the CE immediately contacted the FBI and San Jose Police Department and reported both former employees to the California Department of Public Health Licensing Division It also worked with Mandiant, a digital forensics firm, to ensure internal safeguards were implemented to restrict patient’s PHI only to authorized employees, revised its policies and procedures, and retrained workforce members. The CE provided OCR with additional documentation including its HIPAA Notice of Privacy Practices Policy, as relevant to this breach investigation. OCR obtained assurances that the CE implem
What is known
| People affected | 800 (as reported to HHS) |
|---|---|
| Disclosed | Jun 30, 2017 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| California Attorney General breach notice: White Blossom Care Centeroag.ca.gov · Official notice | Official notice |
| HHS OCR breach report (archive, resolved): White Blossom Care Center (Healthcare Provider, CA)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| California AGresidents of CA | Jun 30, 2017 | |
| HHS archivetotal | Jun 30, 2017 | 800 |
History of this record
- 2026-09-25 · attack: unknown to insider · backfill source
- 2026-09-25 · data_types: [] to ["names","health"] · backfill source
- 2026-09-25 · records_basis: empty to hhs · backfill source
- 2026-09-25 · records: empty to 800 · backfill source
- 2026-09-25 · summary: empty to On June 30, 2017, the covered entity (CE), White Blossom Care Center reported that its former employees impermissibly accessed and copied its residents’ protected health information (PHI) while employed at the facility. The breached electro · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.