Back to the register

Premier Medical Associates

ArchivedSubmitted 09/15/2017
State
PA
Covered entity type
Healthcare Provider
Individuals affected
876
Business associate present
No
Type of breach
Unauthorized Access/Disclosure
Location of breached information
Other
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

On August 8, 2017, the covered entity (CE), Premier Medical Associates, received four website submissions informing them that patients were getting suspicious “phishing” emails from the CE with an attachment requesting protected health information (PHI). The CE investigated the incident and discovered that the suspicious emails were coming from a personal g-mail account and determined that a website misconfiguration made by the webmaster on July 24, 2017, inadvertently permitted access to the public. The misconfiguration was corrected on August 9, 2017, and the CE terminated the contracted services with the webmaster. The CE added an email fraud alert to every page of its website, placed a fraud alert on its phone system, and sent messages to 24,000 patients through the patient portal informing patients of the fraudulent email. The CE created a list of anyone who made submissions to the website in order to determine what type of information had been accessed and who may have viewed the web pages from July 24, 2017, through August 8, 2017 and determined that the breach affected 875 individuals. The CE provided breach notification to HHS, affected individuals, and the media. The CE eliminated the capability of website viewers to make any type of online submissions through the patient portal. The CE reached contacted Google and Bing to have the submissions removed from the internet, which was confirmed on August 30, 2017. The CE developed several new policies regarding their website administration, security, and privacy. OCR reviewed a copy of the CE’s current risk assessment, its breach notification to the affected individuals, as well as copies of relevant policies and procedures. OCR obtained assurances that the CE implemented the corrective actions listed.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.