- State
- NJ
- Covered entity type
- Healthcare Provider
- Individuals affected
- 533
- Business associate present
- No
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
Cornerstone Foot & Ankle, the covered entity (CE), discovered that a former staff member sent spreadsheets containing protected health information (PHI) to her personal email account. The breach affected 533 individuals and the PHI involved included names, insurance information, claims information, dates of treatment, and current procedural terminology (CPT) codes. The CE provided breach notifications to HHS, all affected individuals, and the media. Following the breach, the covered entity conducted an internal investigation including a full enterprise-wide audit. Cornerstone Foot & Ankle implemented mandatory encryption on all outgoing e-mails, obtained a signed and notarized statement from the former employee stating that all emails sent to her personal email account had been deleted, and retrained staff on the provisions of the Privacy and Security Rules. OCR obtained assurances that the covered entity implemented the corrective actions noted above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.