Back to the register

Recovery Institute of the South East P.A.

ArchivedSubmitted 10/21/2017
State
FL
Covered entity type
Healthcare Provider
Individuals affected
689
Business associate present
No
Type of breach
Hacking/IT Incident
Location of breached information
Desktop Computer, Electronic Medical Record, Email, Laptop, Network Server, Other, Other Portable Electronic Device, Paper/Films
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

On October 21, 2017, the Recovery Institute of the South East, P.A., the covered entity (CE), reported that a former employee remotely accessed its computers without authorization between December 2016 and October 2017. The CE reported that 689 individuals were affected; however, a subsequent forensic investigation by Envista Forensics found no evidence of malware, unauthorized access, or unauthorized data exfiltration. Based on these findings, the CE concluded that protected health information (PHI) was not exposed and no patients were affected. During this review, OCR found that although there was no breach, the CE did not have adequate policies or procedures in place to safeguard PHI. OCR provided technical assistance to the CE, and in response, the CE adopted and implemented a comprehensive set of policies and procedures to comply with HIPAA requirements. OCR also conducted outreach with the CE and has obtained assurances that the CE implemented the voluntary corrective actions noted above.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.