- State
- TN
- Covered entity type
- Healthcare Provider
- Individuals affected
- 15,995
- Business associate present
- No
- Type of breach
- Hacking/IT Incident
- Location of breached information
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On February 26, 2018, the covered entity (“CE”), Knoxville Heart Group, Inc., discovered that an unauthorized third party gained access to its email system through a phishing email. The email system contained the protected health information (PHI) of 15,008 individuals, primarily on “rounding lists,” which contained demographic, clinical and healthcare claims information, as well as the Social Security numbers, driver’s licenses, and financial account numbers for 130 individuals. Prior to OCR’s investigation, the CE immediately terminated the unauthorized access, reset the email account password, blocked all internal emails coming from the compromised email account, retrained all of its employees, provided free credit monitoring services and identity theft insurance to individuals whose financial information was compromised and created a secure email messaging platform for its practitioners to use on mobile devices. After the commencement of OCR’s investigation, the CE conducted a risk analysis and revised its Security Rule policies and procedures to prevent reoccurrence. OCR provided the CE with technical assistance of risk analysis and management plans as well as phishing prevention. The CE provided breach notification to HHS, the media, affected individuals, and on its website. OCR obtained assurances that the CE met its notification requirements and implemented the corrective actions listed above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.