- State
- AL
- Covered entity type
- Healthcare Provider
- Individuals affected
- 1,349
- Business associate present
- No
- Type of breach
- Theft
- Location of breached information
- Laptop
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On October 10, 2016,the covered entity (CE), Lister Healthcare Corporation, discovered that a physician employee downloaded protected health information (PHI) from the CE’s electronic health records (EHR) system on her last day of employment. The PHI downloaded by the employee included the PHI of patients that she had never treated in any capacity and that she sought to solicit. The types of PHI involved in the breach included patients' names, addresses, dates of birth, gender, social security numbers, telephone numbers, email addresses, employment status, marital status, race, ethnicity and insurance payer information, and potentially affecting 1, 349 individuals. The CE provided breach notification to HHS, affected individuals, and the media. In response to the breach, the CE contacted its EHR provider to prevent employees from downloading, printing or otherwise transferring any PHI from the EHR system without first obtaining the express approval of the CE’s Chief Executive Officer. Additionally, the CE hired outside counsel to re-train its workforce members regarding HIPAA and their obligations with respect to this breach. The CE also reviewed its HIPAA policies and procedures to strengthen them as appropriate to prevent another incident such as this breach incident or another breach of PHI from occurring again in the future. OCR obtained assurances that the CE implemented the corrective actions listed above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.