- State
- VA
- Covered entity type
- Healthcare Provider
- Individuals affected
- 4,686
- Business associate present
- No
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- Electronic Medical Record
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
The covered entity (CE) reported that from January 3, 2003, through May 10, 2018, a staff member accessed the protected health information (PHI) of 4,686 individuals without a legitimate business reason and that two other employees were aware, but did not report it. The types of PHI involved in the breach included demographic, financial, and clinical information. The CE provided breach notification to HHS, affected individuals, and the media. Following the breach, the CE increased safeguards by monitoring all user access and setting alerts for certain types of access. The CE sanctioned the employee who accessed the records without a business need along with the two employees who knew of the inappropriate access and failed to report it, which in this case included termination of employment for all three. OCR obtained assurances that the CE retrained its entire workforce on its policies and procedures.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.