- State
- IL
- Covered entity type
- Healthcare Provider
- Individuals affected
- 1,185
- Business associate present
- No
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- Network Server
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On June 14, 2016, the covered entity (CE), Carle Foundation Hospital, learned that its business associate (BA), The Claro Group, placed files containing protected health information (PHI) on a public computer server on February 17, 2016, potentially allowing them to become viewable via the internet. The breach affected 1,185 individuals and included demographic and clinical information as well as account numbers assigned by the CE. The CE provided breach notification to HHS, affected individuals, and the media and posted substitute notice on its website. Following the breach, the CE disabled the file transfer protocol (FTP) account where the breach occurred, reviewed all documents in the account directory for sensitive data, and migrated all users of the generic account to individual accounts. The CE also set a timeline for the implementation of various recommended controls, including two-factor authentication for all remote access to the FTP server, data loss prevention tools, configuration of appropriate logging to critical systems, and requiring high-risk vendors to complete an attestation of HIPAA Privacy and Security Rule compliance. The CE demonstrated that at the time of the breach it had a current BA agreement with the BA with provisions regarding the use, disclosure, and safeguarding of PHI. OCR obtained documented assurances that the CE implemented the corrective action steps listed here.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.