- State
- MD
- Covered entity type
- Health Plan
- Individuals affected
- 5,000
- Business associate present
- No
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- Other
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
An employee of the covered entity’s (CE) network penetration testing team discovered protected health information (PHI) on open shares in a network attached storage device that could have affected 5,000 individuals if the IT department had not caught the problem in time. There was no indication of a breach and the CE immediately secured the website and notified the facility to delete all emails. The CE implemented a mandatory monthly training for all site managers to include a discussion of all site incidents.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.