Back to the register

American Anesthesiology, Inc.

ArchivedSubmitted 12/04/2013
State
FL
Covered entity type
Healthcare Provider
Individuals affected
1,000
Business associate present
No
Type of breach
Unauthorized Access/Disclosure
Location of breached information
Paper/Films
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

The covered entity’s (CE) business associate (BA), Financial Imaging, LLC, erroneously mailed 1,000 patient invoices to the wrong patients. The types of protected health information (PHI) involved in the breach included patients’ names, dates of service, and procedures performed. The BA sent breach notification letters to affected individuals and reimbursed the CE for all costs associated with breach notification it provided to the media. Following the breach, the BA revised its quality assurance process to ensure the accuracy of future print jobs and counseled and retrained the staff involved in the breach. The CE had a BA agreement in place and policies that were in compliance with the HIPAA Rules. OCR obtained assurances that CE and BA implemented the corrective actions listed above.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.