Back to the register

Commonwealth Health Corporation

ArchivedSubmitted 03/01/2017
State
KY
Covered entity type
Healthcare Provider
Individuals affected
697,800
Business associate present
No
Type of breach
Unauthorized Access/Disclosure
Location of breached information
Other Portable Electronic Device
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

Commonwealth Health Corporation, the covered entity (CE), discovered that, in August 2014 and February 2015, an employee impermissibly disclosed the protected health information (PHI) of 117,425 patients to a vendor. The types of PHI included billing information, patients’ names, addresses, social security numbers, health insurance information, diagnoses, procedure codes and charges for medical services. The CE sent timely breach notification to HHS. Pursuant to a law enforcement delay, the CE did not send individual notification, media notification or post notification on its website until March 21, 2017, and March 24, 2017. In response to the breach, the CE sanctioned the party responsible for the breach, retrained staff, adopted new policies and procedures, revised existing policies and procedures, and formalized existing procedures that were not previously in writing. OCR also provided technical assistance regarding safeguards for reactivating users in its IT system. OCR obtained assurances that the CE implemented the corrective actions listed above.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.