- State
- GA
- Covered entity type
- Business Associate
- Individuals affected
- 10,104
- Business associate present
- No
- Type of breach
- Hacking/IT Incident
- Location of breached information
- Network Server
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On June 10, 2014, 24 ON Physicians, the covered entity (CE), discovered that its business associate (BA), PST Services, hired an off-shore subcontractor GeBBS, which repurposed a computer server containing the protected health information (PHI) of 10,104 of the CE’s patients. The re-use of server made the PHI potentially available over the Internet from December 1, 2013, to April 17, 2014. The PHI included patients' names, invoice numbers, procedure codes, charge amounts, balances due, policy numbers, billing-related status comments, and dates of service. In response to this breach, the CE ensured that the server was taken off-line and the PHI was destroyed. The subcontractor submitted documentation stating that all of the breached PHI was destroyed. The CE informed OCR that it no longer works with the subcontractor. The CE provided breach notification to HHS, affected individuals and the media. It also provided affected individuals with one year of free credit monitoring. The CE initiated a plan to work with its BAs to strengthen security protocols to prevent this type of breach from occurring in the future. OCR obtained assurances that the CE and BA implemented the corrective actions listed above..
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.