- State
- GA
- Covered entity type
- Healthcare Provider
- Individuals affected
- 654
- Business associate present
- No
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
The Atlanta Center for Reproductive Medicine, the covered entity (CE), discovered that, on July 12, 2013, an employee unintentionally attached the wrong file to an email sent to one patient. The file contained protected health information (PHI) including the names, dates of birth, addresses, medical record numbers, social security numbers, conditions, and treatment and diagnostic information for 654 individuals. The CE obtained assurances that the file containing PHI was destroyed and not used or disclosed to any other parties. The CE provided timely breach notification to HHS, to affected individuals, and the media. In response to the breach, the CE revised its policies and procedures concerning the transmission of PHI via email, and provided additional training to its staff. OCR obtained assurances that the CE implemented the corrective actions listed above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.