- State
- NV
- Covered entity type
- Healthcare Provider
- Individuals affected
- 2,098
- Business associate present
- No
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- Paper/Films
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
The covered entity (CE) failed to renew a business associate agreement (BAA) with a vendor, resulting in a breach of protected health information (PHI), affecting 2,098 individuals. The PHI involved in the breach included names, dates of birth, medical record numbers, admission dates and times, admission diagnoses, and insurance information. The CE took a number of steps to strengthen its monitoring of BAA’s, including hiring a contract coordinator and developing a contracts review committee. The CE renewed the BAA and reviewed the BA’s procedures for safeguarding PHI. OCR’s investigation resulted in improved practices regarding safeguarding PHI.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.