- State
- MO
- Covered entity type
- Healthcare Provider
- Individuals affected
- 6,845
- Business associate present
- No
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- Paper/Films
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
The covered entity (CE), James R. Etzkorn, M.D. (Etzkorn), reported that the contents of its server was encrypted in a ransomware attack. After this breach incident was reported, Etzkorn reported an additional breach incident in which protected health information (PHI) was inadvertently mailed to the wrong recipients. These breaches affected 6,845 individuals. OCR consolidated the investigations into the subject review. The PHI involved in both incidents included names, clinical information, claims information, and diagnostic codes. The practice implemented administrative, technical, and security safeguards. In addition, Etzkorn conducted a risk analysis and implemented a risk management plan. OCR obtained assurances that the CE implemented the corrective steps noted above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.