- State
- VA
- Covered entity type
- Healthcare Provider
- Individuals affected
- 552
- Business associate present
- No
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- Other
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
A staff member inadvertently faxed 552 patients' billing statements to a law firm without an authorization when responding to a medical records request for two clients of the law firm. The billing statements contained protected health information (PHI), specifically, names and diagnoses. The covered entity (CE) provided breach notification to HHS, affected individuals, and the media. Following the breach, the CE obtained verbal and written confirmation from the law firm that it shredded and/or permanently deleted all copies of the PHI. OCR obtained assurances that the CE implemented the corrective actions listed above. The staff member responsible for the faxing error is no longer employed at the CE.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.