- State
- PA
- Covered entity type
- Healthcare Provider
- Individuals affected
- 537
- Business associate present
- Yes
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- Other Portable Electronic Device
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
A business associate (BA), Ambucor Health Solutions, for the covered entity (CE), Lebanon Cardiology Associates, reported a breach by a rogue employee. The CE and BA both reported the breach to HHS. The BA's employee, who is now incarcerated on unrelated matters, downloaded protected health information (PHI) onto two portable computer drives (i.e., "thumb" drives) which have been recovered. The types of PHI that were involved varied by patient, but may have included the first and last names, phone numbers, diagnoses, medications, dates of birth, race, home addresses, testing data, patient identification numbers, and medical device information of 537 of the CE’s patients. In addition, the thumb drives contained the social security numbers of about 650 patients of several covered entities with PHI that was also affected by the same breach incident. OCR reviewed a copy of the signed BA agreement between the BA and the CE. OCR confirmed that breach notification letters were mailed to affected individuals on June 27, 2016. This investigation has been consolidated into an existing review filed by the BA to ensure that all the requirements under the Breach Notification Rule have been met. OCR obtained assurances that the CE implemented the corrective actions listed above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.