- State
- GA
- Covered entity type
- Healthcare Provider
- Individuals affected
- 1,175
- Business associate present
- No
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On May 30, 2014, a staff member sent an email to approximately 1,175 patients that erroneously permitted them to see the email addresses of all recipients. The covered entity (CE), St. Francis Hospital, investigated the incident, replaced its information technology department leadership and its security officer, and counseled the employee involved. Additionally, the CE updated its HIPAA policies and trained the entire workforce on its updated policies. The CE also began upgrading its equipment to better prevent security incidents. The CE provided breach notification to the affected individuals via e-mail message, sent notification to the media, and placed a conspicuous notice on its website. In response to OCR’s provision of technical assistance, the CE provided written notification to the affected individuals.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.