- State
- TX
- Covered entity type
- Healthcare Provider
- Individuals affected
- 6,800
- Business associate present
- Yes
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- Other
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
A business associate (BA), Zirmed, Inc., erroneously mailed notices that contained other patients’ names and dates of services due to a programming error by its sub-contractor, Allison Payment Systems (APS). The breach affected approximately 6,800 individuals. The CE initially provided breach notification to HHS and affected individuals. Following the breach, the covered entity (CE), Preventice Services, LLC, worked with the BA and its sub-contractor to correct the programming error and add an additional technical safeguard. OCR confirmed that appropriate BA agreements were in place prior to the breach, provided technical assistance regarding media notification requirements, and confirmed that the CE completed the required breach notifications, including the posting of substitute notice on its website.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.