- State
- FL
- Covered entity type
- Healthcare Provider
- Individuals affected
- 1,647
- Business associate present
- Yes
- Type of breach
- Hacking/IT Incident
- Location of breached information
- Network Server
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On July 28, 2017, OCR informed the covered entity (CE), Advanced Orthopedic Center, that in October 2015 a former employee of a website vendor, CoPilot Provider Support Services (“CoPilot”), impermissibly accessed protected health information (PHI) that the CE had entered in an online tool offered by a medicine manufacturer (DePuy Synthes Mitek Sports Medicine). The breach affected approximately 1,647 of the CE’s patients and included demographic and medical insurance card information (including social security numbers). CoPilot provided breach notification to affected individuals and the media on behalf of the CE before the CE was informed about the breach. As a result of OCR’s investigation, the CE provided breach notification to HHS, documented the impermissible disclosure in each affected patient’s file, revised its Notice of Privacy Practices, executed business associate (BA) agreements with its BAs, and obtained satisfactory assurances that each BA will appropriately safeguard PHI pursuant to HIPAA. The CE ceased using the website portal involved in the breach and started confirming insurance coverage directly with each patient. OCR obtained documented assurances that the CE established a process to execute BA agreements with all of its vendors in accordance to the Privacy Rule and implemented the compliance action steps listed above. OCR provided technical assistance to the CE regarding the Breach Notification Rule and BA agreements.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.