Back to the register

Orleans Medical Clinic

ArchivedSubmitted 08/19/2016
State
IN
Covered entity type
Healthcare Provider
Individuals affected
6,890
Business associate present
No
Type of breach
Hacking/IT Incident
Location of breached information
Network Server
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

Hackers gained access to the covered entity’s (CE) unsecured computer server from April 5, 2016, through April 17, 2016, after its business associate (BA), ProBleu, upgraded its servers and left a port open to the internet. The server contained the protected health information (PHI) of approximately 6,890 individuals, including demographic and clinical information. The CE, Orleans Medical Clinic (OMC), provided breach notification to HHS, affected individuals, and the media on August 19, 2016, and also reported the breach to the Indiana Attorney General’s office and the FBI. To prevent similar breaches from happening in the future, OMC retained Pondurance, a forensic information technology firm. Pondurance concluded that the BA failed to take the necessary steps to secure the CE’s server by implementing the required technical safeguards. The CE terminated its relationship with the BA in July of 2016, created a policy and procedure regarding the Breach Notification requirements, and trained its workforce on its security awareness policies and procedures. OCR provided technical assistance and obtained documented assurances that the CE implemented the corrective actions listed above.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.