- State
- CO
- Covered entity type
- Healthcare Provider
- Individuals affected
- 1,357
- Business associate present
- No
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- Electronic Medical Record
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On May 30, 2018, Dino-Peds, the covered entity (CE), reported that one of its former providers disclosed his patients protected health information (PHI) to the hospital where the provider was moving his services and the hospital used this information to send a patient notification about the provider's move. The PHI included the names and addresses of 1,357 individuals. The provider had proper access to the information when he pulled it from his records, but the CE was unaware that the provider would be instructing the hospital to send a mailing. The CE notified the affected individuals on June 1, 2018. OCR provided the CE with technical assistance regarding the CE’s obligations to safeguard PHI and to ensure it has met its Breach Notification Rule obligations.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.