- State
- SC
- Covered entity type
- Healthcare Provider
- Individuals affected
- 1,997
- Business associate present
- No
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- Electronic Medical Record
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On July 27, 2015, the covered entity, Bon Secours St. Francis Health Systems, Inc., received a complaint that an employee was committing insurance fraud involving billing co-workers’ insurance for an experimental topical cream. The CE audited the electronic system containing protected health information (PHI) and concluded on October 15, 2015, that the employee accessed the PHI of 1,997 patients without a discernible professional need. The types of PHI involved in the breach included patients' names, dates of birth, addresses, diagnoses, treatment plans, and scanned insurance cards and driver’s licenses. The CE provided breach notification to HHS, affected individuals, and the media. In response to this incident, the CE reviewed its policies, re-trained staff, and assessed whether behavior-based auditing software programs would be an appropriate addition to current security measures. OCR obtained assurances that the CE implemented the corrective actions listed above. The CE also terminated the involved employee's employment.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.