- State
- OH
- Covered entity type
- Healthcare Provider
- Individuals affected
- 6,441
- Business associate present
- No
- Type of breach
- Hacking/IT Incident
- Location of breached information
- Network Server
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
The covered entity (CE) filed a breach report and verified the information in the breach report. Later, the CE stated it filed the breach report prematurely and there was no breach. The CE then filed a breach report recanting that a breach had occurred. Based on the conflicting breach reports filed by the CE, OCR decided to initiate an investigation to determine the CE’s compliance. The CE provided affidavits signed by its business associate (BA) for the software used to run the practice and where PHI is stored, and its information technology person at CORTCOMP-Cortland Computer. Both stated that PHI was not accessed or compromised. OCR obtained and reviewed a copy of the BA agreement with the software vendor, the CE’s policies and procedures related to safeguarding PHI, a risk analysis, and an incident report.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.