- State
- FL
- Covered entity type
- Healthcare Provider
- Individuals affected
- 689
- Business associate present
- No
- Type of breach
- Hacking/IT Incident
- Location of breached information
- Desktop Computer, Electronic Medical Record, Email, Laptop, Network Server, Other, Other Portable Electronic Device, Paper/Films
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On October 21, 2017, the Recovery Institute of the South East, P.A., the covered entity (CE), reported that a former employee remotely accessed its computers without authorization between December 2016 and October 2017. The CE reported that 689 individuals were affected; however, a subsequent forensic investigation by Envista Forensics found no evidence of malware, unauthorized access, or unauthorized data exfiltration. Based on these findings, the CE concluded that protected health information (PHI) was not exposed and no patients were affected. During this review, OCR found that although there was no breach, the CE did not have adequate policies or procedures in place to safeguard PHI. OCR provided technical assistance to the CE, and in response, the CE adopted and implemented a comprehensive set of policies and procedures to comply with HIPAA requirements. OCR also conducted outreach with the CE and has obtained assurances that the CE implemented the voluntary corrective actions noted above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.