- State
- MN
- Covered entity type
- Healthcare Provider
- Individuals affected
- 2,568
- Business associate present
- Yes
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- Other
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
Virtual Radiologic Professionals (VRad), the covered entity (CE), reported that its vendor, MedData, a business associate (BA), experienced a programming error which caused the protected health information (PHI) of 846 individuals to be sent to the wrong recipients. When investigating this breach, MedData discovered that an additional programming error caused the PHI of 2,590 individuals to be entered into the incorrect billing records and also sent to the wrong recipients. VRad notified HHS, affected individuals, and the media. Substitute notice was also posted on its website. MedData revised its software to correct the errors. OCR provided technical assistance regarding vRad’s compliance obligations under the HIPAA Security Rule. As a result of OCR’s investigation, vRad developed and revised relevant procedures and developed an inventory of its business associates and its associated agreements. OCR obtained assurances that the aforementioned corrective actions were implemented.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.