- State
- FL
- Covered entity type
- Business Associate
- Individuals affected
- 500
- Business associate present
- Yes
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- Network Server
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On August 16, 2018, First Coast Podiatric Surgery and Wound, the covered entity (“CE”), discovered that its billing software, managed by its business associate (“BA”), NextGen, had experienced an IT incident causing the log-in page for one clinic to show as the log-in page for other clinics. The CE initially reported that approximately 500 individuals were affected, but after further investigation, the CE concluded that no protected health information (PHI) was involved in the IT incident. Though an IT incident occurred, the log-in page still required authorized username and password information in order to access any PHI; and PHI was not at any time accessed by unauthorized individuals. Because the CE determined there was no reportable breach of PHI, and no affected individuals, it did not provide individual notification. OCR obtained assurances that no reportable breach occurred.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.