Back to the register

Midwest Orthopaedics at Rush, LLC

ArchivedSubmitted 03/31/2014
State
IL
Covered entity type
Healthcare Provider
Individuals affected
1,256
Business associate present
No
Type of breach
Hacking/IT Incident
Location of breached information
Email
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

On February 10, 2014, an unknown party gained unauthorized access to the personal email account of a physician at Midwest Orthopaedics at Rush, the covered entity (CE), disclosing protected health information (PHI) that affected approximately 1,256 individuals. The emails contained electronic PHI including names, physicians' surgical schedules, surgical descriptions, codes, dates and instructions. The CE provided breach notification to HHS, affected individuals, and the media. The CE also conducted an investigation and determined the root cause of the breach. Additionally, the CE disabled the physician’s Gmail account to which the PHI was sent, and trained the physician and his staff on the use of the secure email. The CE revised email procedures by eliminating all external email addresses from the CE's distribution list of physicians and support staff and discontinued the use of outside email addresses for sending or receiving of PHI. OCR obtained documented assurances that the CE implemented the corrective actions listed above.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.