- State
- KY
- Covered entity type
- Healthcare Provider
- Individuals affected
- 697,800
- Business associate present
- No
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- Other Portable Electronic Device
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
Commonwealth Health Corporation, the covered entity (CE), discovered that, in August 2014 and February 2015, an employee impermissibly disclosed the protected health information (PHI) of 117,425 patients to a vendor. The types of PHI included billing information, patients’ names, addresses, social security numbers, health insurance information, diagnoses, procedure codes and charges for medical services. The CE sent timely breach notification to HHS. Pursuant to a law enforcement delay, the CE did not send individual notification, media notification or post notification on its website until March 21, 2017, and March 24, 2017. In response to the breach, the CE sanctioned the party responsible for the breach, retrained staff, adopted new policies and procedures, revised existing policies and procedures, and formalized existing procedures that were not previously in writing. OCR also provided technical assistance regarding safeguards for reactivating users in its IT system. OCR obtained assurances that the CE implemented the corrective actions listed above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.