- State
- NC
- Covered entity type
- Healthcare Provider
- Individuals affected
- 13,674
- Business associate present
- Yes
- Type of breach
- Hacking/IT Incident
- Location of breached information
- Network Server
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
Uncommon Care, P.A., the covered entity (CE), discovered that its business associate (BA), Bizmatics, Inc., was the victim of a computer hacking incident. The incident resulted in potential unauthorized access to the CE’s electronic medical records stored on Bizmatics’ servers. The breach affected 13,674 individuals and included patients' addresses, dates of birth, names, social security numbers, diagnoses, test results, medications, and other treatment information. The CE sent timely breach notification to HHS, to affected individuals, and to the media. The CE also posted notification about the breach on its website. In response to the breach, the CE offered one year of free credit monitoring to the affected individuals. Prior to OCR's investigation, the CE determined that its BA agreement with the BA was not fully executed and entered into an effective BA agreement on June 7, 2016. The CE decided to continue its services contract with the BA and obtained assurances from the BA that improvements have been and will be made to its computer network, servers, and network monitoring activities. OCR obtained assurances that the CE implemented the corrective actions listed above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.