Back to the register
Ambucor Health Solutions, an unincorporated division of The ScottCare Corporation
ArchivedSubmitted 07/22/2016
- State
- DE
- Covered entity type
- Business Associate
- Individuals affected
- 1,679
- Business associate present
- Yes
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- Email, Other Portable Electronic Device
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
Ambucor Health Solutions is a business associate (BA) utilized by multiple covered entities (CEs) to provide remote monitoring services for cardiac devices. The BA reported that on March 17, 2016, a rogue employee downloaded thousands of its files containing protected health information (PHI) onto a portable "thumb" drive, while he was under indictment for federal crimes, including felony identity theft in a matter unrelated to the BA. The BA immediately shut off the employee's computer access and conducted a thorough investigation. The former employee was incarcerated and cooperated with federal law enforcement authorities. Eventually, the thumb drives were returned to the BA and a computer forensic firm and data review team identified a total of 53 CEs, which included approximately 53,000 individual patients affected by the breach. The types of PHI affected by the breach varied by patient and may have included patients' first and last names, phone numbers, diagnoses, medications, dates of birth, addresses, testing data and results, medical device information, enrollment dates and physicians' names as well as 650 patients' social security numbers. The BA provided breach notification to HHS and its 53 customers (the CEs), as well as all affected individuals that its customers asked it to notify. The BA offered identity protection services to all affected individuals at no cost and provided a call center to respond to questions and concerns. Following the breach, the BA re-ran background checks on all of its management team. In addition, it performed a comprehensive enterprise-wide risk assessment, reconfigured the universal serial bus (USB) ports on its computer workstations to allow read-only access, and enhanced its related policies and procedures. It also provided additional HIPAA training to all employees. OCR obtained assurances that the BA implemented the corrective actions listed. In this case, the BA's sanction of the involved employee included termination of employment.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.