- State
- CO
- Covered entity type
- Healthcare Provider
- Individuals affected
- 1,310
- Business associate present
- No
- Type of breach
- Hacking/IT Incident
- Location of breached information
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
James Kagan, MD, reported that an employee was subject to a phishing attack resulting in unauthorized access to an email account containing patient information. Upon investigation, OCR determined that James Kagan, MD is not a covered entity or business associate subject to the HIPAA Privacy, Security, and Breach Notification Rules.
Change history
- 9/23/2026Added to OCR's archive list
Source: U.S. Department of Health and Human Services, Office for Civil Rights, Breach Portal. Records are reproduced as published; entity names and figures are OCR's.