Back to the register

Serene Sedation, LLC

ArchivedSubmitted 03/14/2018
State
MD
Covered entity type
Healthcare Provider
Individuals affected
5,207
Business associate present
No
Type of breach
Hacking/IT Incident
Location of breached information
Network Server
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

An unauthorized user accessed the computer network of a business associate (BA) which stored the covered entity's (CE) financial records. The server contained the protected health information (PHI) of approximately 5,207 individuals, including demographic and financial information. Following the breach, the CE discontinued storing financial records on its BA's networks, and increased its own security by adding encryption. OCR reviewed the CE’s risk analysis and BA agreements. OCR obtained assurances that the CE took immediate steps to increase the security of ePHI by encrypting its computer hard drives, encrypting outgoing e-mails, and using a virtual private network (VPN). The CE provided breach notification to HHS, affected individuals, and the media.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.