- State
- AZ
- Covered entity type
- Healthcare Provider
- Individuals affected
- 1,049
- Business associate present
- Yes
- Type of breach
- Hacking/IT Incident
- Location of breached information
- Other
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
A security researcher accessed the covered entity's electronic protected health information (ePHI) due to a vulnerability in a business associate's (BA) data storage system. The researcher reportedly did not intend to use or disclose the information. The breach affected 1,049 individuals and involved in the breach included names, addresses, birthdates, driver's license numbers, social security numbers, and clinical information such as diagnoses, lab results, and medications. The CE provided breach notification to HHS, affected individuals, and the media. Following the breach, the BA returned the ePHI to the covered entity. The BA was closing its business at the time of the breach and is now out of business. OCR obtained a copy of the CE's BA agreement with this BA. As a result of OCR’s investigation the CE increased its awareness of its responsibilities with respect to its BAs.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.