- State
- MD
- Covered entity type
- Healthcare Provider
- Individuals affected
- 4,831
- Business associate present
- No
- Type of breach
- Hacking/IT Incident
- Location of breached information
- Other
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
The covered entity (CE), Neurology Physicians, reported that in February, 2010, it entered into a medical transcription services agreement with a business associate (BA) located in Bangalore, India that provides dictation and transcription services for the physicians. On May 23, 2016, a patient discovered the office notes from her visit were viewable online. The CE learned that the transcribed files were uploaded onto a public Hypertext Markup Language (HTML) folder that was publicly searchable. The breach affected 4,831 individuals and included clinical information. The CE does not have any evidence that transcription files were actually viewed or acquired by any third parties; however, it acted in an abundance of caution in response to the breach due to the potential that the transcription files became publicly searchable at some point between 2010 and 2016, and the inability to determine if any third parties may have viewed the transcription files. To the best of the CE's knowledge, only the two patients who discovered the breach and the individuals involved in the investigation and remediation of the breach on behalf of the CE actually viewed any PHI and did not retain it. OCR reviewed the CE's risk analysis and BA agreements. The CE terminated its relationship with the BA. The CE stated that it ensured a detailed risk assessment was conducted to identify any vulnerabilities and a gap analysis work plan was developed and worked through to address such vulnerabilities. Additionally, the CE installed a new server with fully updated security settings and updated its Notice of Privacy Practices. OCR obtained assurances that CE implemented the corrective action listed above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.