- State
- IL
- Covered entity type
- Healthcare Provider
- Individuals affected
- 2,080
- Business associate present
- No
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- Network Server
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
The covered entity (CE) mistakenly permitted protected health information (PHI) to be viewable on the Internet when users uploaded files without changing the default permission settings for the folders containing the files. As a result, Google was able to detect and cache the PHI in the uploaded folders. Approximately 2,080 individuals were affected by this breach. The types of PHI involved in the breach included students’ names, birthdates, genders, identification numbers, vision exam dates, diagnoses, and schools. The CE provided breach notification to HHS, the parents and guardians of affected individuals, and the media. It also posted notice on its website. The CE took action to remove the files containing PHI from its network and compiled a list of files along with the associated unique record locator numbers (URLs) and cached URLs. The CE contacted Google to request removal of the data from the cache and the archives, and Google confirmed that the data was removed. OCR obtained assurances that the CE implemented the corrective actions listed above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.