Back to the register

MedEvolve

ArchivedSubmitted 07/10/2018
State
AR
Covered entity type
Business Associate
Individuals affected
205,434
Business associate present
Yes
Type of breach
Unauthorized Access/Disclosure
Location of breached information
Network Server
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

Today, the U.S. Department of Health and Human Services’ Office for Civil Rights (OCR) announced a settlement with MedEvolve, Inc. (“MedEvolve”), a business associate that provides practice management, revenue cycle management, and practice analytics software services to health care entities. The settlement was signed to resolve a data breach resulting from the misconfiguration of a File Transfer Protocol (“FTP”) server that caused the protected health information of 230,572 individuals to be unsecure and accessible on the internet. The potential violations of the Health Insurance Portability and Accountability Act (HIPAA) include the lack of an analysis to determine risks and vulnerabilities to electronic protected health information across the organization, and the failure to enter into a Business Associate Agreement with a subcontractor. As a result MedEvolve paid $350,000 to OCR and agreed to implement a corrective action plan, which identifies steps MedEvolve will take to resolve these potential violations and protect the security of electronic patient health information. “Ensuring that security measures are in place to protect electronic protected health information where it is stored is an integral part of cybersecurity and the protection of patient privacy,” said OCR Director Melanie Fontes Rainer. “HIPAA-regulated entities must ensure that they are not leaving patient health information unsecured on network servers available to the public via the internet.” In July 2018, OCR initiated an investigation of MedEvolve following the receipt of a breach notification report stating that a FTP server containing electronic protected health information was openly accessible to the internet. The information included patient names, billing addresses, telephone numbers, primary health insurer and doctor's office account numbers, and in some cases Social Security numbers. In addition to the monetary settlement, MedEvolve will undertake a comprehensive corrective action plan that will be monitored for two years by OCR to ensure compliance with the HIPAA Security Rule. MedEvolve has agreed to take the following steps: • Conduct an accurate and thorough risk analysis to determine risks and vulnerabilities to electronic patient/system data across the organization • Develop and implement a risk management plan to address and mitigate identified security risks and vulnerabilities identified in the risk analysis • Develop, maintain, and revise, as necessary, its written policies and procedures to comply with the HIPAA Privacy and Security Rules, • Augment its existing HIPAA and Security Training Program for all MedEvolve workforce members who have access to protected health information, and • Report to HHS within sixty (60) days when workforce members fail to comply with MedEvolve’s written policies and procedures to comply with the HIPAA Privacy and Security Rules.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.