Back to the register
North Carolina Department of Health and Human Services - Division of State Operated Health Care Facilities
ArchivedSubmitted 11/08/2013
- State
- NC
- Covered entity type
- Healthcare Provider
- Individuals affected
- 1,315
- Business associate present
- No
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- Other
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
The covered entity (CE), North Carolina Department of Health and Human Services Division of State Operated Health Care Facilities, impermissibly disclosed the protected health information (PHI) of 1,315 individuals by exposing their PHI on its website, NC Open Book, without authorizations. The PHI involved in the breach included patient payment information, names, addresses, and facility names, which were erroneously posted as vendor payments on the website. The CE removed the information from the website immediately upon discovery. The CE also provided breach notification to HHS, affected individuals, and the media, and placed substitute notice on its website. In addition, the CE provided a toll-free phone number for affected individuals to obtain additional information. Following the breach the CE implemented procedures limiting the types of personally identifiable information that are disclosed in the accounting system. Additionally, the CE improved safeguards for all HIPAA-related documents and email correspondence containing PHI. Finally, the CE implemented a procedure that requires prior review of any data being released to the public and redaction of confidential information. OCR obtained assurances that the corrective actions listed above were completed.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.