Back to the register

Asante

ArchivedSubmitted 09/09/2016
State
OR
Covered entity type
Healthcare Provider
Individuals affected
2,400
Business associate present
No
Type of breach
Unauthorized Access/Disclosure
Location of breached information
Electronic Medical Record
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

OCR investigated the covered entity (CE), Asante, after the CE reported a breach of 2,399 individuals’ electronic protected health information (ePHI) due to a workforce member’s inappropriate access to medical records for a couple of years. It also informed OCR of similar incidents during the course of the investigation involving other workforce members. The breaches affected patients' names, ages, locations in the hospital, certain health information, and patients' status. Following the breaches and in response to OCR’s investigation, the CE sanctioned the workforce members involved and implemented a zero tolerance sanctions policy for patient information misuse. OCR obtained documentation that the CE completed security enhancements and network modifications in 2016 and 2017. Additionally, OCR obtained assurances that the CE plans to take additional measures to increase its administrative and technical safeguards of ePHI in 2017 and 2018. In this case, the employee sanctions included termination of employment.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.