- State
- IN
- Covered entity type
- Healthcare Provider
- Individuals affected
- 6,890
- Business associate present
- No
- Type of breach
- Hacking/IT Incident
- Location of breached information
- Network Server
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
Hackers gained access to the covered entity’s (CE) unsecured computer server from April 5, 2016, through April 17, 2016, after its business associate (BA), ProBleu, upgraded its servers and left a port open to the internet. The server contained the protected health information (PHI) of approximately 6,890 individuals, including demographic and clinical information. The CE, Orleans Medical Clinic (OMC), provided breach notification to HHS, affected individuals, and the media on August 19, 2016, and also reported the breach to the Indiana Attorney General’s office and the FBI. To prevent similar breaches from happening in the future, OMC retained Pondurance, a forensic information technology firm. Pondurance concluded that the BA failed to take the necessary steps to secure the CE’s server by implementing the required technical safeguards. The CE terminated its relationship with the BA in July of 2016, created a policy and procedure regarding the Breach Notification requirements, and trained its workforce on its security awareness policies and procedures. OCR provided technical assistance and obtained documented assurances that the CE implemented the corrective actions listed above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.