- State
- GA
- Covered entity type
- Business Associate
- Individuals affected
- 24,113
- Business associate present
- Yes
- Type of breach
- Hacking/IT Incident
- Location of breached information
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
EyeSouth Partners is the business associate (BA) for Cobb Eye Center, South Georgia Eye Partners, Georgia Eye Associates, and Georgia Ophthalmology, the covered entities (CEs). On October 25, 2018, the BA discovered that an unauthorized third party gained access to an employee’s email account from September 11, 2018, through October 25, 2018. Via a forensic investigation, on December 19, 2018, the BA identified four email attachments that contained protected health information (PHI) belonging to the CEs. The breach affected 24,113 individuals' PHI and included demographic and claims information. The BA provided breach notification to HHS, to the media, and to the affected individuals. The BA also provided the CEs with web notification that the CEs timely posted to their websites. In response to the breach, the BA changed the employee’s email account password, quarantined his computer, reviewed all parts of its computer server that the employee's computer could access, implemented dual factor authentication, deployed new software for spam filtering and malware, reset controls on its email tenant, and improved safeguards for logins to email accounts. The BA also provided training to its employees. During OCR’s investigation, OCR discovered that not all employees at the BA were participating in regular HIPAA training. OCR provided technical assistance regarding the BA’s training responsibilities, and in response, the BA identified an employee who is now responsible for ensuring that all employees participate in HIPAA training and provided OCR with documentation evidencing that all employees participated in HIPAA training in 2018. OCR obtained assurances that the CE implemented the corrective actions listed above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.