- State
- AL
- Covered entity type
- Business Associate
- Individuals affected
- 1,145
- Business associate present
- Yes
- Type of breach
- Hacking/IT Incident
- Location of breached information
- Network Server
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On January 10, 2014, a business associate (BA), PracMan, Inc., of two covered entities (CE), Monarch Women’s Health (Monarch) and Punuru J.M. Reddy, M.D., Inc. (Dr. Reddy), impermissibly disclosed the protected health information (PHI) of the CEs’ patients when the BA’s technology subcontractor, MASHNet, copied and stored computer files in error on an unsecured server. The PHI included demographic, clinical, and financial information, including names, account numbers, insurance providers, procedures, diagnoses, social security numbers (SSN), and account balances affecting approximately 1,179 of Dr. Reddy’s patients and approximately 1,145 of Monarch’s patients. The BA provided breach notification to HHS, affected individuals, and the media. It also established a toll-free number and website dedicated to providing information regarding the breach, and offered one year of free credit monitoring to individuals whose SSN was potentially exposed online. In response to the breach, the BA engaged a third party to perform a risk analysis of its operations and updated its privacy and security policies. The BA ensured that the data was removed from the unsecured server and all cached copies of links to the PHI were removed. OCR obtained assurances that the BA implemented the corrective actions listed above. Additionally, the BA terminated its relationship with the subcontractor and restructured its corporate network.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.