- State
- NJ
- Covered entity type
- Healthcare Provider
- Individuals affected
- 1,654
- Business associate present
- No
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- Network Server, Other
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
Virtua Medical Group, the covered entity (CE), reported a breach by its transcription vendor when the business associate unintentionally misconfigured its server leading to exposure of the transcription documents via an internet search engine. The CE estimated the transcription documents may have included the electronic protected health information (ePHI) of 1,654 patients’ names, birthdates and treatment information from office visits. The CE provided breach notification to HHS, the media, and the affected individuals, and posted notice to its website. As a result of OCR’s investigation, the CE contacted law enforcement, and contacted the transcription vendor to facilitate the removal of the entire site at issue from Google cache. The CE received assurances that Google removed the individual patient records that were accessible via searching the internet and that no other search engine was involved. The CE also terminated its relationship with the transcription vendor. Additionally, the CE is expected to take additional corrective actions in connection with the consent judgment entered into by CE with the Attorney General of the State of New Jersey and the New Jersey Division of Consumer Affairs.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.