- State
- TX
- Covered entity type
- Healthcare Provider
- Individuals affected
- 501
- Business associate present
- No
- Type of breach
- Theft
- Location of breached information
- Paper/Films
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
The Center for Health Care Services, the covered entity (CE), reported that a former workforce member impermissibly disclosed the electronic protected health information (ePHI) of 28,434 individuals to an unauthorized third party without authorization. The types of PHI disclosed included patients’ names, dates of birth, social security numbers, laboratory results, and dates of services. The CE provided breach notification to HHS, affected individuals, and the media. OCR obtained documented assurances that the CE created new policies, trained workforce members on its new policies, and improved technical safeguards to prevent similar incidents.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.