- State
- TX
- Covered entity type
- Health Plan
- Individuals affected
- 8,700
- Business associate present
- Yes
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- Other
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
The business associate (BA) of Lone Star Circle of Care, the Covered Entity (CE) reported a breach of unsecured protected health information which affected 8,700 individuals. The breach was the result of a backup file inadvertently uploaded by the BA onto the CE’s website. The file contained the protected health information of patients who used the website to request appointments, prescription refills or other inquiries. The CE secured the data contained in the backup file, removed the pages that individuals use to make appointments and refill requests, and disabled the mobile application. The CE also terminated its business associate agreement with the BA, Marketing Clique. Further, during the investigation, OCR received confirmation that the BA was no longer doing business. The CE provided breach notification to HHS, the media, and the affected individuals. OCR examined CE’s policies concerning administrative, physical and technical safeguards implemented by the CE. As a result of the investigation, OCR provided technical assistance to the CE regarding the risk analysis and risk management plan and breach notification to individuals. The CE provided OCR with documentation of the corrective actions taken.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.