- State
- LA
- Covered entity type
- Healthcare Provider
- Individuals affected
- 824
- Business associate present
- No
- Type of breach
- Hacking/IT Incident
- Location of breached information
- Desktop Computer
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
An unauthorized user remotely accessed a workstation computer from the covered entity (CE), Center for Neurosurgical & Spine Disorders, LLC. The types of protected health information (PHI) accessed by the unauthorized user included the names, addresses, phone numbers, social security numbers, medical chart information, and billing information of 824 individuals. Upon discovering the breach, the CE notified the Federal Bureau of Investigation, notified the three major consumer credit reporting agencies, and provided free credit monitoring to affected individuals. The CE provided breach notification to HHS, affected individuals, and the media. Further, the CE improved its technical security posture and retrained staff. OCR obtained assurances that the CE implemented the corrective actions listed.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.