- State
- OR
- Covered entity type
- Healthcare Provider
- Individuals affected
- 1,506
- Business associate present
- No
- Type of breach
- Hacking/IT Incident
- Location of breached information
- Desktop Computer
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On February 29, 2016, the covered entity (CE), Atique Orthodontics, reported that files on its web server were compromised by a potential unauthorized access through one of its computers. The files on the server contained the names, dates of birth, addresses, phone numbers, credit card numbers, insurance information, and social security numbers of approximately 1,506 individuals. The CE provided breach notification to HHS and affected individuals and offered identity theft protection services. Following the breach, the CE disconnected the computer from the network server, reconfigured it, and disabled the remote desktop connection. The CE also implemented access controls, upgraded its firewall and anti-virus and other anti-malware protection software, and encrypted its electronic protected health information (ePHI). Additionally, the CE developed a plan to perform periodic system audits, adopted policies and procedures to ensure that ePHI is not stored on laptops, desktops, or other mobile device, and updated its log-off policy for unattended computers. The CE also inventoried hardware and software which is stored off site and updated workforce members' training with the new policies and procedures. OCR obtained assurances from the CE that it implemented the corrective actions listed above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.