- State
- TX
- Covered entity type
- Healthcare Provider
- Individuals affected
- 653
- Business associate present
- No
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- Other
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
Dr. Kraig R. Pepper, D.O., P.A. the covered entity (CE) reported that CoPilot Provider Support Services (CoPilot) suffered a data security incident exposing the protected health information (PHI) of 653 patients of the CE. The electronic PHI (ePHI) included patients’ names, addresses, dates of birth, claims information, diagnosis, and social security numbers. Following the breach, the CE provided breach notification to HHS, the media and affected individuals. As a result of OCR’s investigation, the CE executed a business associate agreement with CoPilot and revised its authorization form regarding permitted disclosures of PHI. The CE also provided one year of identity theft protection services to affected individuals. The CE is expected to perform a thorough and accurate risk analysis, establish a risk management plan, execute agreements with other business associates and document the impermissible disclosure of the affected patient’s PHI for accounting of disclosures purposes. Further, the CE is expected to perform a technical and non-technical evaluation in response to any environmental or operational changes affecting the security of ePHI that establishes the extent to which the CE’s security policies and procedures meet the requirements of the HIPAA Security Rule.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.