Back to the register

Episcopal Health Services Inc. d/b/a St. John's Episcopal Hospital

ArchivedSubmitted 06/25/2015
State
NY
Covered entity type
Healthcare Provider
Individuals affected
509
Business associate present
Yes
Type of breach
Theft
Location of breached information
Electronic Medical Record
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

OCR opened an investigation of the covered entity (CE), Episcopal Health Services Inc., d/b/a St. John’s Episcopal Hospital, after it reported that its business associate's (BA) employee sold 509 patients' data to unknown persons. The protected health information (PHI) included patients’ names, addresses, dates of birth, gender, email addresses, social security numbers, account numbers, dates of service, medications, insurance information, diagnoses, billing codes, and reasons for treatment. The BA, Zotec Partners, LLC, d/b/a Medical Management LLC, also filed a separate breach report. As a result of the breach, the BA transitioned to an improved billing system that offers more security controls, implemented software for tracking and monitoring access and user activity, and masked social security numbers from employees whose job duties do not require full access. In addition, the BA conducted updated training on the Privacy and Security Rule standards for all employees. OCR obtained assurances for this case that the BA implemented the corrective actions noted above and also opened a separate investigation of the BA.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.