- State
- FL
- Covered entity type
- Healthcare Provider
- Individuals affected
- 2,000
- Business associate present
- No
- Type of breach
- Theft
- Location of breached information
- Desktop Computer, Other Portable Electronic Device
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
The covered entity (CE), Pointe Medical Services, Inc., discovered on February 11, 2016, that a former nurse practitioner was soliciting patients to her new practice from information she had downloaded from the CE between October 23, 2015 and until she was terminated on December 15, 2015. Information on the reports included: patients' names, dates of birth, phone numbers, reasons for appointments, appointment status (i.e. no show, cancelled, etc.), service sites, diagnoses, conditions, and health insurance information including insurance providers and plan types. The breach affected 2,055 patients. The CE provided breach notification to HHS, to affected individuals, on its website and to various media outlets across Georgia and Florida. In response to the breach, the CE retrained its workforce, disabled the ability to download information to removable electronic storage devices, and increased the frequency of its electronic health record activity audits. OCR obtained assurances that the CE implemented the corrective actions listed above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.