- State
- ND
- Covered entity type
- Healthcare Provider
- Individuals affected
- 2,000
- Business associate present
- No
- Type of breach
- Theft
- Location of breached information
- Paper/Films
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
The covered entity (CE), Kemmet Dental Design, learned on November 11, 2013, that its office had been broken into over the preceding weekend. At the time of the break-in, the CE stored between 1,500 – 2,000 paper patient charts containing protected health information (PHI) in its office, and the paper patient charts were not further secured inside the office. The CE provided breach notification to HHS and affected individuals. Though the CE indicated that nothing appeared to be missing, it moved its dental office to a different location in July 2014 and implemented safeguards it had lacked prior to the break-in. For example, the CE converted all of its patient charts to a secure electronic medical record system, properly shredded its old x-rays, and properly disposed of its old paper charts. It also improved physical security. OCR provided technical assistance regarding the need to implement safeguards policies and procedures and regarding the CE's breach notification reporting obligations.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.